Re: no DHCP-assigned InitiatorName

[email protected] Mon, 22 Sep 2008 11:41:12 -0400
Newsgroups gmane.ietf.ips
Message-ID <[email protected]>
This is a multi-part message in MIME format.

--===============0493778013==
Content-class: urn:content-classes:message
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C91CC9.A3E41668"

This is a multi-part message in MIME format.

------_=_NextPart_001_01C91CC9.A3E41668
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

CbCS is a technology for which there is little to no current product
support.  As a security technology, it does not strike me as a good
solution to the issue that Michael raises, which is basically an
automatic configuration issue.

Thanks,
--David
----------------------------------------------------
David L. Black, Distinguished Engineer
EMC Corporation, 176 South St., Hopkinton, MA  01748
+1 (508) 293-7953             FAX: +1 (508) 293-7786
[email protected]        Mobile: +1 (978) 394-7754
----------------------------------------------------

________________________________

	From: [email protected] [mailto:[email protected]] On
Behalf Of Julian Satran
	Sent: Monday, September 22, 2008 9:29 AM
	To: Michael Howard
	Cc: Sivan Tal; [email protected]
	Subject: Re: [Ips] no DHCP-assigned InitiatorName
=09
=09
	Michael,=20
=09
	I think that some of the OSs have the initiator name wired into
the image and boot providers will have to set this name.=20
	I am not sure how what exactly is required for each version.=20
	The boot RFC defines where the image comes from but very little
else.=20
=09
	Sivan may give you a pointer to CbCS.=20
=09
	Regards,=20
	Julo=20
=09
=09
=09
=09
=09
From: 	Michael Howard <[email protected]>=20
To: 	Julian Satran/Haifa/IBM@IBMIL=20
Cc: 	[email protected]=20
Date: 	09/22/2008 09:19=20
Subject: 	Re: [Ips] no DHCP-assigned InitiatorName

________________________________




=09
=09
	Julian Satran wrote:
	> Michael - I am not sure what you are looking for? A standard
parameter=20
	> as those described by the iBOOT RFC?
=09
	Yes, I am looking for a specific DHCP parameter that defines
what=20
	InitiatorName is to be used by the iSCSI boot client.
=09
	It seems to me that the purpose of RFC4173 was/is to allow
stateless=20
	clients to boot. The target parameters that are specified in
RFC4173 are=20
	necessary, but not sufficient. On many commercial iSCSI target
servers=20
	you must have the InitiatorName in order to be able to log in to
the=20
	target. This is the case for NetApp and SANRAD, and I strongly
for many=20
	others.
=09
	> In any case the initiator name is not the only way to control
what a=20
	> server will access.
	>=20
	> CbCS (stands for Credential Based Command Security) available
for any=20
	> SCSI device at the SCSI layer (see the T10 site) is probably=20
	> safer/better and does not depend on things that can be so easy
faked by=20
	> an initiator as the initiator name and may be easier to
deploy.
=09
	This is not something that I am familiar with ...
=09
	*** 10 minutes later ***
=09
	I could find no reference to CbCS or Command Based Command
Security at=20
	the NetApp support site now.netapp.com
=09
	A quick search at www.t10.org didn't turn anything up either ...
I'll=20
	keep looking.
=09
=09
	There may (and should) be other/better security mechanisms
working their=20
	way through the standardization and implementation processes.
=09
	As a practical measure, I believe that a DHCP-supplied
InitiatorName is=20
	needed because InitiatorName is required by many commercial
iSCSI target=20
	servers.
=09
=09
	Michael
=09
=09
=09
=09


------_=_NextPart_001_01C91CC9.A3E41668
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<META content=3D"MSHTML 6.00.2900.3395" name=3DGENERATOR></HEAD>
<BODY>
<DIV><SPAN class=3D933443815-22092008><FONT face=3D"Courier New" =
size=3D2>CbCS is a=20
technology for which there is little to no current =
product</FONT></SPAN></DIV>
<DIV><SPAN class=3D933443815-22092008><FONT face=3D"Courier New"=20
size=3D2>support.&nbsp; </FONT></SPAN><SPAN =
class=3D933443815-22092008><FONT=20
face=3D"Courier New" size=3D2>As a security technology, it does not =
strike me as a=20
good</FONT></SPAN></DIV>
<DIV><SPAN class=3D933443815-22092008><FONT face=3D"Courier New" =
size=3D2>solution to=20
the </FONT></SPAN><SPAN class=3D933443815-22092008><FONT face=3D"Courier =
New"=20
size=3D2>issue that Michael raises, which&nbsp;is=20
basically&nbsp;an</FONT></SPAN></DIV>
<DIV><SPAN class=3D933443815-22092008><FONT face=3D"Courier New" =
size=3D2>automatic=20
configuration </FONT></SPAN><SPAN class=3D933443815-22092008><FONT=20
face=3D"Courier New" size=3D2>issue.</FONT></SPAN></DIV><!-- Converted =
from text/plain format -->
<P><!-- Converted from text/plain format --></P>
<P><FONT size=3D2><FONT=20
face=3D"Courier =
New">Thanks,<BR>--David<BR>----------------------------------------------=
------<BR>David=20
L. Black, Distinguished Engineer<BR>EMC Corporation, 176 South St., =
Hopkinton,=20
MA&nbsp; 01748<BR>+1 (508)=20
293-7953&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;=20
FAX: +1 (508)=20
293-7786<BR>[email protected]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
=20
Mobile: +1 (978)=20
394-7754<BR>----------------------------------------------------</FONT></=
FONT></P>
<BLOCKQUOTE=20
style=3D"PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #000000 2px =
solid; MARGIN-RIGHT: 0px">
  <DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr align=3Dleft>
  <HR tabIndex=3D-1>
  <FONT face=3DTahoma size=3D2><B>From:</B> [email protected]=20
  [mailto:[email protected]] <B>On Behalf Of </B>Julian=20
  Satran<BR><B>Sent:</B> Monday, September 22, 2008 9:29 =
AM<BR><B>To:</B>=20
  Michael Howard<BR><B>Cc:</B> Sivan Tal; =
[email protected]<BR><B>Subject:</B> Re:=20
  [Ips] no DHCP-assigned InitiatorName<BR></FONT><BR></DIV>
  <DIV></DIV><FONT face=3Dsans-serif size=3D2>Michael,</FONT> =
<BR><BR><FONT=20
  face=3Dsans-serif size=3D2>I think that some of the OSs have the =
initiator name=20
  wired into the image and boot providers will have to set this =
name.</FONT>=20
  <BR><FONT face=3Dsans-serif size=3D2>I am not sure how what exactly is =
required=20
  for each version.</FONT> <BR><FONT face=3Dsans-serif size=3D2>The boot =
RFC defines=20
  where the image comes from but very little else.</FONT> <BR><BR><FONT=20
  face=3Dsans-serif size=3D2>Sivan may give you a pointer to =
CbCS.</FONT>=20
  <BR><BR><FONT face=3Dsans-serif size=3D2>Regards,</FONT> <BR><FONT =
face=3Dsans-serif=20
  size=3D2>Julo</FONT> <BR><BR><BR><BR><BR>
  <TABLE width=3D"100%">
    <TBODY>
    <TR vAlign=3Dtop>
      <TD><FONT face=3Dsans-serif color=3D#5f5f5f size=3D1>From:</FONT>=20
      <TD><FONT face=3Dsans-serif size=3D1>Michael Howard=20
        &lt;[email protected]&gt;</FONT>=20
    <TR vAlign=3Dtop>
      <TD><FONT face=3Dsans-serif color=3D#5f5f5f size=3D1>To:</FONT>=20
      <TD><FONT face=3Dsans-serif size=3D1>Julian =
Satran/Haifa/IBM@IBMIL</FONT>=20
    <TR>
      <TD vAlign=3Dtop><FONT face=3Dsans-serif color=3D#5f5f5f =
size=3D1>Cc:</FONT>=20
      <TD><FONT face=3Dsans-serif size=3D1>[email protected]</FONT>=20
    <TR vAlign=3Dtop>
      <TD><FONT face=3Dsans-serif color=3D#5f5f5f size=3D1>Date:</FONT>=20
      <TD><FONT face=3Dsans-serif size=3D1>09/22/2008 09:19</FONT>=20
    <TR vAlign=3Dtop>
      <TD><FONT face=3Dsans-serif color=3D#5f5f5f =
size=3D1>Subject:</FONT>=20
      <TD><FONT face=3Dsans-serif size=3D1>Re: [Ips] no DHCP-assigned=20
        InitiatorName</FONT></TR></TBODY></TABLE><BR>
  <HR noShade>
  <BR><BR><BR><TT><FONT size=3D2><BR><BR>Julian Satran wrote:<BR>&gt; =
Michael - I=20
  am not sure what you are looking for? A standard parameter <BR>&gt; as =
those=20
  described by the iBOOT RFC?<BR><BR>Yes, I am looking for a specific =
DHCP=20
  parameter that defines what <BR>InitiatorName is to be used by the =
iSCSI boot=20
  client.<BR><BR>It seems to me that the purpose of RFC4173 was/is to =
allow=20
  stateless <BR>clients to boot. The target parameters that are =
specified in=20
  RFC4173 are <BR>necessary, but not sufficient. On many commercial =
iSCSI target=20
  servers <BR>you must have the InitiatorName in order to be able to log =
in to=20
  the <BR>target. This is the case for NetApp and SANRAD, and I strongly =
for=20
  many <BR>others.<BR><BR>&gt; In any case the initiator name is not the =
only=20
  way to control what a <BR>&gt; server will access.<BR>&gt; <BR>&gt; =
CbCS=20
  (stands for Credential Based Command Security) available for any =
<BR>&gt; SCSI=20
  device at the SCSI layer (see the T10 site) is probably <BR>&gt; =
safer/better=20
  and does not depend on things that can be so easy faked by <BR>&gt; an =

  initiator as the initiator name and may be easier to =
deploy.<BR><BR>This is=20
  not something that I am familiar with ...<BR><BR>*** 10 minutes later=20
  ***<BR><BR>I could find no reference to CbCS or Command Based Command =
Security=20
  at <BR>the NetApp support site now.netapp.com<BR><BR>A quick search at =

  </FONT></TT><A href=3D"www.t10.org"><TT><FONT=20
  size=3D2>www.t10.org</FONT></TT></A><TT><FONT size=3D2> didn't turn =
anything up=20
  either ... I'll <BR>keep looking.<BR><BR><BR>There may (and should) be =

  other/better security mechanisms working their <BR>way through the=20
  standardization and implementation processes.<BR><BR>As a practical =
measure, I=20
  believe that a DHCP-supplied InitiatorName is <BR>needed because =
InitiatorName=20
  is required by many commercial iSCSI target=20
  =
<BR>servers.<BR><BR><BR>Michael<BR></FONT></TT><BR><BR><BR></BLOCKQUOTE><=
/BODY></HTML>

------_=_NextPart_001_01C91CC9.A3E41668--

--===============0493778013==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Ips mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ips

--===============0493778013==--