Re: Benjamin Kaduk's Discuss on draft-ietf-mboned-ieee802-mcast-problems-11: (with DISCUSS and COMMENT)
Benjamin Kaduk <[email protected]> Thu, 9 Jan 2020 08:48:34 -0800
| Newsgroups | gmane.ietf.mboned |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Jan 09, 2020 at 05:51:13AM -0800, Alvaro Retana wrote: > On January 8, 2020 at 5:20:00 PM, Benjamin Kaduk via Datatracker wrote: > = > Hi! > = > > ---------------------------------------------------------------------- > > DISCUSS: > > ---------------------------------------------------------------------- > > > > Section 9 says that "[RFC4601], for instance, mandates the use of IPsec > > to ensure authentication of the link-local messages in the Protocol > > Independent Multicast - Sparse Mode (PIM-SM) routing protocol" but I > > could not find where such use of IPsec was mandated. (I do recognize > > that a similar statement appears almost verbatim in RFC 5796, but RFC > > 5796 seems focused on extending PIM-SM to support ESP in additon to the > > AH usage that was the main focus of the RFC 4601 descriptions, and does > > not help clarify the RFC 4601 requirements for me.) The closest I found > > was in Section 6.3.1 of RFC 4601: "The network administrator defines an > > SA and SPI that are to be used to authenticate all link-local PIM > > protocol messages (Hello, Join/Prune, and Assert) on each link in a PIM > > domain" but I do not think that applies to all usage of PIM-SM. Am I > > missing something obvious? > = > It looks like everyone (including me) missed the nit that rfc4601 has > been Obsoleted by rfc7761. =A0One of the changes between the two is that > rfc7761 removed the requirement for authentication using IPSec "due to > lack of sufficient implementation and deployment experience". I think Roman did pick up on the obsoletion, but it was buried in the nits at the end of his ballot position. As you rightly note, this does supersede my specific objection to this document (though I still would like to know which part of RFC 4601 made this requirement, if only to know whether or not to file an erratum on 5796). > This is what rfc7761 says about authentication: > = > =A0 =A06.3. =A0Authentication > = > =A0 =A0 =A0 This document refers to RFC 5796 [8], which specifies mechani= sms to > =A0 =A0 =A0 authenticate PIM-SM link-local messages using the IPsec Encap= sulating > =A0 =A0 =A0 Security Payload (ESP) or (optionally) the Authentication Hea= der > =A0 =A0 =A0 (AH). =A0It also points out that non-link-local PIM-SM messag= es (i.e., > =A0 =A0 =A0 Register and Register-Stop messages) can be secured by a norm= al > =A0 =A0 =A0 unicast IPsec Security Association (SA) between two communica= nts. And that seems like a good treatment of the situation. Thanks, Ben _______________________________________________ MBONED mailing list [email protected] https://www.ietf.org/mailman/listinfo/mboned