Re: [IPv6] [Last-Call] Artart last call review of draft-ietf-6man-rfc6874bis-02
David Farmer <[email protected]>
| Newsgroups | gmane.ietf.apps-discuss,gmane.ietf.ipv6 |
|---|---|
| Message-ID | <CAN-Dau1-sfBTXew1u=qGuWrO3FGBPTNDXk=ByTx324Xy_XyDig@mail.gmail.com> |
On Mon, Mar 27, 2023 at 15:10 Brian E Carpenter <[email protected]> wrote: > Roy, > On 28-Mar-23 07:26, Roy T. Fielding wrote: > > On Mar 26, 2023, at 7:33 PM, Brian E Carpenter < > [email protected]> wrote: > >> On 27-Mar-23 14:37, Rob Sayre wrote: > >>> On Sun, Mar 26, 2023 at 6:31 PM Brian E Carpenter < > [email protected] <mailto:[email protected]>> wrote: > >>> I 100% fail to understand what you mean. > >>> http://[fe80::abcd-eth0] won't parse today any better than http://[fe80::abcd%eth0]. > Neither of them respects the current grammar. Whatever we do here extends > the grammar. > > > > The difference is that % is only allowed within a pct-encoding and that > > is heavily enforced at all layers, including those that don't parse the > URI, > > because it can be used for vulnerability probing/exploitation. > > Let me see if I can paraphrase that. It seems that you are saying that > even if the strict ABNF grammar permits a bare % all (or at least many) > implementations will still not allow it? So, RFC 3986, section 2.4, paragraph 3, basically says “%” can only be use for percent-encoding, although it doesn’t use the word “only”, which would make the statement much more unequivocal. Also, I agree the ABNF is fuzzy about bare “%” or anything other than two hex digits following percent sign. I'm at a loss to understand the vunerability, though. The proposal is that > exactly one bare % is allowed but only within the [ ] pair. There is no > requirement for percent-encoding within the [ ] pair otherwise. If > percent-encoding was supported there, something like http://[fe80::abc%64] > would work today. But percent-encoding is not supported there, because no > version of the syntax says it is. The only security discussion of percent-encodings is in section 7.3 of RFC 3986, where it clearly warns about %00 or (NUL) and the need for special handling. So, I also would like to better understand the venerability claims. Thanks -- =============================================== David Farmer Email:[email protected] Networking & Telecommunication Services Office of Information Technology University of Minnesota 2218 University Ave SE Phone: 612-626-0815 Minneapolis, MN 55414-3029 Cell: 612-812-9952 =============================================== _______________________________________________ art mailing list [email protected] https://www.ietf.org/mailman/listinfo/art