Re: KINK issue list rev.2

Michael Thomas <[email protected]> Wed, 02 Feb 2005 12:19:30 -0800
Newsgroups gmane.ietf.kink
Organization Cisco Systems
Message-ID <[email protected]>
On Wed, 2005-02-02 at 11:06, Sam Hartman wrote:
> >>>>> "Shoichi" == Shoichi Sakane <[email protected]> writes:
> 
>     >> Speaking as an individual, normally when there is a major
>     >> version and a minor version the intent is that using a greater
>     >> minor version than one side expects is acceptable.
> 
>     Shoichi> correct.  do you comment that the document does not touch
>     Shoichi> a minor version ?
> 
> Correct.  The only thing I find is an invalid minor version error and
> a requirement that implementations MUST use version 1.0.  It doesn't
> say what happens if a recipient receives a greater minor version.
> 
> Again, if the WG wants to use minor versions the same as major
> versions, that's OK but needs to be called out because it is not what
> people expect.

From a jaded perspective: when is the last time a minor
version on a protocol has actually helped? Or for that
matter a major version?

Usually the semantics of major/minor or non-backward
compatible vs. backward compatible. That is, a receiver
MUST be able to deal with a higher minor version and
just ignore things it doesn't understand. But as I say,
in practice things get a lot messier. Maybe this would
be a way to deal with new IKEv2 stuff, but it's all
rather dependent on what morphed with phase 2 payloads.

So I'm rather ambivalent. The current phrasing will certainly
do it's main job: stopping a receiver from incorrectly parsing
future versions and the potential exploits that could result.
Maybe we really should leave it at that if for no other
reason from a security/system analysis standpoint.

		Mike
signature.asc (application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iQCVAwUAQgE10rMsDAj/Eq++AQJ51QQAw+qigg2pW+C4ufJR/3AyZafDoo+kAVwL
XIK/tzdOpGfl3tLJAeaKUCHQZOk7eoZk39kR/nr/u+3FnSaFV+BqxqT0LjQ+YOe0
nI/lj1IBBPKMg6VnFrSTQoq5buOpN8L2rqE/hiNsC3HMv2emCOUJEo107iczU9sR
yxTTuFwQWCY=
=FImx
-----END PGP SIGNATURE-----