Re: no DHCP-assigned InitiatorName
[email protected] Mon, 22 Sep 2008 11:41:12 -0400
| Newsgroups | gmane.ietf.ips |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============0493778013== Content-class: urn:content-classes:message Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C91CC9.A3E41668" This is a multi-part message in MIME format. ------_=_NextPart_001_01C91CC9.A3E41668 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable CbCS is a technology for which there is little to no current product support. As a security technology, it does not strike me as a good solution to the issue that Michael raises, which is basically an automatic configuration issue. Thanks, --David ---------------------------------------------------- David L. Black, Distinguished Engineer EMC Corporation, 176 South St., Hopkinton, MA 01748 +1 (508) 293-7953 FAX: +1 (508) 293-7786 [email protected] Mobile: +1 (978) 394-7754 ---------------------------------------------------- ________________________________ From: [email protected] [mailto:[email protected]] On Behalf Of Julian Satran Sent: Monday, September 22, 2008 9:29 AM To: Michael Howard Cc: Sivan Tal; [email protected] Subject: Re: [Ips] no DHCP-assigned InitiatorName =09 =09 Michael,=20 =09 I think that some of the OSs have the initiator name wired into the image and boot providers will have to set this name.=20 I am not sure how what exactly is required for each version.=20 The boot RFC defines where the image comes from but very little else.=20 =09 Sivan may give you a pointer to CbCS.=20 =09 Regards,=20 Julo=20 =09 =09 =09 =09 =09 From: Michael Howard <[email protected]>=20 To: Julian Satran/Haifa/IBM@IBMIL=20 Cc: [email protected]=20 Date: 09/22/2008 09:19=20 Subject: Re: [Ips] no DHCP-assigned InitiatorName ________________________________ =09 =09 Julian Satran wrote: > Michael - I am not sure what you are looking for? A standard parameter=20 > as those described by the iBOOT RFC? =09 Yes, I am looking for a specific DHCP parameter that defines what=20 InitiatorName is to be used by the iSCSI boot client. =09 It seems to me that the purpose of RFC4173 was/is to allow stateless=20 clients to boot. The target parameters that are specified in RFC4173 are=20 necessary, but not sufficient. On many commercial iSCSI target servers=20 you must have the InitiatorName in order to be able to log in to the=20 target. This is the case for NetApp and SANRAD, and I strongly for many=20 others. =09 > In any case the initiator name is not the only way to control what a=20 > server will access. >=20 > CbCS (stands for Credential Based Command Security) available for any=20 > SCSI device at the SCSI layer (see the T10 site) is probably=20 > safer/better and does not depend on things that can be so easy faked by=20 > an initiator as the initiator name and may be easier to deploy. =09 This is not something that I am familiar with ... =09 *** 10 minutes later *** =09 I could find no reference to CbCS or Command Based Command Security at=20 the NetApp support site now.netapp.com =09 A quick search at www.t10.org didn't turn anything up either ... I'll=20 keep looking. =09 =09 There may (and should) be other/better security mechanisms working their=20 way through the standardization and implementation processes. =09 As a practical measure, I believe that a DHCP-supplied InitiatorName is=20 needed because InitiatorName is required by many commercial iSCSI target=20 servers. =09 =09 Michael =09 =09 =09 =09 ------_=_NextPart_001_01C91CC9.A3E41668 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD> <META http-equiv=3DContent-Type content=3D"text/html; = charset=3Dus-ascii"> <META content=3D"MSHTML 6.00.2900.3395" name=3DGENERATOR></HEAD> <BODY> <DIV><SPAN class=3D933443815-22092008><FONT face=3D"Courier New" = size=3D2>CbCS is a=20 technology for which there is little to no current = product</FONT></SPAN></DIV> <DIV><SPAN class=3D933443815-22092008><FONT face=3D"Courier New"=20 size=3D2>support. </FONT></SPAN><SPAN = class=3D933443815-22092008><FONT=20 face=3D"Courier New" size=3D2>As a security technology, it does not = strike me as a=20 good</FONT></SPAN></DIV> <DIV><SPAN class=3D933443815-22092008><FONT face=3D"Courier New" = size=3D2>solution to=20 the </FONT></SPAN><SPAN class=3D933443815-22092008><FONT face=3D"Courier = New"=20 size=3D2>issue that Michael raises, which is=20 basically an</FONT></SPAN></DIV> <DIV><SPAN class=3D933443815-22092008><FONT face=3D"Courier New" = size=3D2>automatic=20 configuration </FONT></SPAN><SPAN class=3D933443815-22092008><FONT=20 face=3D"Courier New" size=3D2>issue.</FONT></SPAN></DIV><!-- Converted = from text/plain format --> <P><!-- Converted from text/plain format --></P> <P><FONT size=3D2><FONT=20 face=3D"Courier = New">Thanks,<BR>--David<BR>----------------------------------------------= ------<BR>David=20 L. Black, Distinguished Engineer<BR>EMC Corporation, 176 South St., = Hopkinton,=20 MA 01748<BR>+1 (508)=20 293-7953  = ; =20 FAX: +1 (508)=20 293-7786<BR>[email protected] = =20 Mobile: +1 (978)=20 394-7754<BR>----------------------------------------------------</FONT></= FONT></P> <BLOCKQUOTE=20 style=3D"PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #000000 2px = solid; MARGIN-RIGHT: 0px"> <DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr align=3Dleft> <HR tabIndex=3D-1> <FONT face=3DTahoma size=3D2><B>From:</B> [email protected]=20 [mailto:[email protected]] <B>On Behalf Of </B>Julian=20 Satran<BR><B>Sent:</B> Monday, September 22, 2008 9:29 = AM<BR><B>To:</B>=20 Michael Howard<BR><B>Cc:</B> Sivan Tal; = [email protected]<BR><B>Subject:</B> Re:=20 [Ips] no DHCP-assigned InitiatorName<BR></FONT><BR></DIV> <DIV></DIV><FONT face=3Dsans-serif size=3D2>Michael,</FONT> = <BR><BR><FONT=20 face=3Dsans-serif size=3D2>I think that some of the OSs have the = initiator name=20 wired into the image and boot providers will have to set this = name.</FONT>=20 <BR><FONT face=3Dsans-serif size=3D2>I am not sure how what exactly is = required=20 for each version.</FONT> <BR><FONT face=3Dsans-serif size=3D2>The boot = RFC defines=20 where the image comes from but very little else.</FONT> <BR><BR><FONT=20 face=3Dsans-serif size=3D2>Sivan may give you a pointer to = CbCS.</FONT>=20 <BR><BR><FONT face=3Dsans-serif size=3D2>Regards,</FONT> <BR><FONT = face=3Dsans-serif=20 size=3D2>Julo</FONT> <BR><BR><BR><BR><BR> <TABLE width=3D"100%"> <TBODY> <TR vAlign=3Dtop> <TD><FONT face=3Dsans-serif color=3D#5f5f5f size=3D1>From:</FONT>=20 <TD><FONT face=3Dsans-serif size=3D1>Michael Howard=20 <[email protected]></FONT>=20 <TR vAlign=3Dtop> <TD><FONT face=3Dsans-serif color=3D#5f5f5f size=3D1>To:</FONT>=20 <TD><FONT face=3Dsans-serif size=3D1>Julian = Satran/Haifa/IBM@IBMIL</FONT>=20 <TR> <TD vAlign=3Dtop><FONT face=3Dsans-serif color=3D#5f5f5f = size=3D1>Cc:</FONT>=20 <TD><FONT face=3Dsans-serif size=3D1>[email protected]</FONT>=20 <TR vAlign=3Dtop> <TD><FONT face=3Dsans-serif color=3D#5f5f5f size=3D1>Date:</FONT>=20 <TD><FONT face=3Dsans-serif size=3D1>09/22/2008 09:19</FONT>=20 <TR vAlign=3Dtop> <TD><FONT face=3Dsans-serif color=3D#5f5f5f = size=3D1>Subject:</FONT>=20 <TD><FONT face=3Dsans-serif size=3D1>Re: [Ips] no DHCP-assigned=20 InitiatorName</FONT></TR></TBODY></TABLE><BR> <HR noShade> <BR><BR><BR><TT><FONT size=3D2><BR><BR>Julian Satran wrote:<BR>> = Michael - I=20 am not sure what you are looking for? A standard parameter <BR>> as = those=20 described by the iBOOT RFC?<BR><BR>Yes, I am looking for a specific = DHCP=20 parameter that defines what <BR>InitiatorName is to be used by the = iSCSI boot=20 client.<BR><BR>It seems to me that the purpose of RFC4173 was/is to = allow=20 stateless <BR>clients to boot. The target parameters that are = specified in=20 RFC4173 are <BR>necessary, but not sufficient. On many commercial = iSCSI target=20 servers <BR>you must have the InitiatorName in order to be able to log = in to=20 the <BR>target. This is the case for NetApp and SANRAD, and I strongly = for=20 many <BR>others.<BR><BR>> In any case the initiator name is not the = only=20 way to control what a <BR>> server will access.<BR>> <BR>> = CbCS=20 (stands for Credential Based Command Security) available for any = <BR>> SCSI=20 device at the SCSI layer (see the T10 site) is probably <BR>> = safer/better=20 and does not depend on things that can be so easy faked by <BR>> an = initiator as the initiator name and may be easier to = deploy.<BR><BR>This is=20 not something that I am familiar with ...<BR><BR>*** 10 minutes later=20 ***<BR><BR>I could find no reference to CbCS or Command Based Command = Security=20 at <BR>the NetApp support site now.netapp.com<BR><BR>A quick search at = </FONT></TT><A href=3D"www.t10.org"><TT><FONT=20 size=3D2>www.t10.org</FONT></TT></A><TT><FONT size=3D2> didn't turn = anything up=20 either ... I'll <BR>keep looking.<BR><BR><BR>There may (and should) be = other/better security mechanisms working their <BR>way through the=20 standardization and implementation processes.<BR><BR>As a practical = measure, I=20 believe that a DHCP-supplied InitiatorName is <BR>needed because = InitiatorName=20 is required by many commercial iSCSI target=20 = <BR>servers.<BR><BR><BR>Michael<BR></FONT></TT><BR><BR><BR></BLOCKQUOTE><= /BODY></HTML> ------_=_NextPart_001_01C91CC9.A3E41668-- --===============0493778013== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Ips mailing list [email protected] https://www.ietf.org/mailman/listinfo/ips --===============0493778013==--