Re: Issue: When to do return-routability tests (#6)
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote:
> We were considering another option (in early May): That an empty
> informational exchange for RR verification might not work and that we
> should introduce a nonce for liveness of the test. I still like that
> option.
=> if I understand the issue: the attacking peer doesn't get the
RR probe but infers its (empty) content and answers...
This is a related issue, but partly different too. I agree that
empty informational exchanges are not sufficient for an RR
test, and a nonce is needed. Basically, an empty informational
exchange just proves that the answer came from the peer, but
not that it came from the address we wanted to test.
=> I disagree with your wording, the issue is not it came
from the address we wanted to test, it is the peer really got
the probe.
I guess you could amend my list above as follows;
- There was an authenticated answer from the peer, but
it is not guaranteed to be from the tested address
or path to it (because the peer can construct a
response without seeing the request).
=> I really prefer this wording.
The last option corresponds to making an empty informational
exchange. I think the first and the last options are not
practical options; its either the second or the third
option that we should adopt.
=> so it will be the third (informational exchanges with nonces,
BTW IKEv2 doesn't really constraint the contents of informational
messages, so this is compatible/available).
Regards
[email protected]