Re: KINK issue list rev.2
Michael Thomas <[email protected]> Wed, 02 Feb 2005 12:19:30 -0800
| Newsgroups | gmane.ietf.kink |
|---|---|
| Organization | Cisco Systems |
| Message-ID | <[email protected]> |
On Wed, 2005-02-02 at 11:06, Sam Hartman wrote: > >>>>> "Shoichi" == Shoichi Sakane <[email protected]> writes: > > >> Speaking as an individual, normally when there is a major > >> version and a minor version the intent is that using a greater > >> minor version than one side expects is acceptable. > > Shoichi> correct. do you comment that the document does not touch > Shoichi> a minor version ? > > Correct. The only thing I find is an invalid minor version error and > a requirement that implementations MUST use version 1.0. It doesn't > say what happens if a recipient receives a greater minor version. > > Again, if the WG wants to use minor versions the same as major > versions, that's OK but needs to be called out because it is not what > people expect. From a jaded perspective: when is the last time a minor version on a protocol has actually helped? Or for that matter a major version? Usually the semantics of major/minor or non-backward compatible vs. backward compatible. That is, a receiver MUST be able to deal with a higher minor version and just ignore things it doesn't understand. But as I say, in practice things get a lot messier. Maybe this would be a way to deal with new IKEv2 stuff, but it's all rather dependent on what morphed with phase 2 payloads. So I'm rather ambivalent. The current phrasing will certainly do it's main job: stopping a receiver from incorrectly parsing future versions and the potential exploits that could result. Maybe we really should leave it at that if for no other reason from a security/system analysis standpoint. Mike
signature.asc
(application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iQCVAwUAQgE10rMsDAj/Eq++AQJ51QQAw+qigg2pW+C4ufJR/3AyZafDoo+kAVwL XIK/tzdOpGfl3tLJAeaKUCHQZOk7eoZk39kR/nr/u+3FnSaFV+BqxqT0LjQ+YOe0 nI/lj1IBBPKMg6VnFrSTQoq5buOpN8L2rqE/hiNsC3HMv2emCOUJEo107iczU9sR yxTTuFwQWCY= =FImx -----END PGP SIGNATURE-----