[manet] Re: [IPv6]Re: IPv6 Address for Ad Hoc Networks
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.manet,gmane.ietf.ipv6 |
|---|---|
| Message-ID | <[email protected]> |
Hi,
I have read mla-21.
I think the word "amorphously" in paragraph three is not the word you want.
(dictionary.com says "amorphous" means without form, denies existence of
adverb, but such a word ought to exist)
I think the word you want is autonomously, or autonomically.
I don't really understand section 4.
Does a node have an MLA for each network it joins?
Or for each interface on each network it joins?
I think MLAs should be added as loopback addresses on a single interface (lo,
or dummy or null). Then the ad-hoc routing protocol should spread /128
routes for that MLA using the v6-LL of the device as the nexthop.
This is how RFC8994 works, and how most IGPs are configured.
About RFC8994: at first it seems a little less ad-hoc, but given the OMNI
context, I actually reconsider. RFC8994 does allocation of /120 or /116
(from within the ACP's /48 ULA) prefixes via PKIX certificates. (See below)
Yes, this is very very much centrally managed, but it's tied to the
onboarding of the device, and the provisioning of the security credential.
Surely in 2024 ADHOC networks need security, and that means some kind of
credential.
I'm generally skeptical that you need 116-bits of randomness.
I think 64-bits might enough. I don't think you can/should squat on ORCHIDs
or HHITs; or rather, I think we have more than enough v6 space to set aside
some for OMNI.
"If the node becomes aware that the address is
already in use by another node, it instead generates and assigns a
new MLA."
without a mechanism for DAD, I don't see how this statement can ever be
enacted.
I think you should consider if you truly and really need/want such random
addresses. I think you will ultimately need a secured identity.
i.e:
X509v3 extensions:
X509v3 Subject Alternative Name:
otherName:[email protected]
as per section 6.11.5 of RFC8994, I allocate "Vlong" style addresses so that
the nodes have not just a /128 for themselves, but also some additional
addresses for local VMs, containers or different (virtual) services.
(No, these prefixes are not for extending the network, but for network
management. If a device needed a /64 for SLAAC, then it would get one via
DHCPv6 over the production network, not the ACP)
--
Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting )
Sandelman Software Works Inc, Ottawa and Worldwide
_______________________________________________
manet mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE----- iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmavyWsWHG1jcitpZXRm QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZVorB/0XUHZini7b9R8s9+neAcItkPU1 NO8KGduMO0g0zT7QnDLHDo02zPwWDZKGL9007H3Egoyw0KsH27ZJCnNSvNgT6tqa DPRFnPDUBe/PEKnMwmR2yqriXcic5Tiusd4rx8NVUAIutMNiWQfaip7gNVfuprNG /pPhaX5rD4qQ75jOreHDlaAkFSwykn3gMt+2g2shFS9AO6ekn9jfBSi0lQ4SiaMR 0brL5tKxxwQPNh1Ql6/2iLsbiV6/HU/uO91O/gOgBRRAP4Ecja4mqxNV7qDiDXn0 neRNdLRI4EVoyQixJTBHPDUD4WQvV7Caw2fAwcUqeqZ80YXoLgj8PI3WIJVg =1OQS -----END PGP SIGNATURE-----