Re: WGLC on the design draft

Francis Dupont <[email protected]> Wed, 04 Jan 2006 12:43:14 +0100
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   > I strongly disagree: not authenticate the IP addresses just leaves
   > the protocol vulnerable to attacks modifying them, i.e., you can
   > establish the IKE SA and IPsec SAs with a bad address (cf what I call
   
   The IP addresses in the IP header are not authenticated. That is state
   of fact.
   
=> yes but the protocol document addresses this issue so I simply suggest
to put the same text into the design document.

   Only solution to fix that would be running MOBIKE over AH, which would
   authenticate the IP address in the *IP header*.
   
   So this text here tells that if protocol uses those address from the
   *IP header* it needs to take care. 
   
=> I agree but to explain how is not bad, is it?

   >  - reflect the IP address in messages in order to detect changes.
   >    This is the option used by Mobike which requires either NAT dectection
   >    or NAT prevention
   
   This option does not make IP addresses in the *IP header*
   authenticated. It will make separate copy of the IP addresses in the
   payload, which will be then authenticated, and those can be used in
   places where the unauthenticatede IP addresses from the *IP header*
   cannot be used.
   
=> strictly you're right but this is not how it is implemented (as the
options are not copies but hashes of the IP addresses the IP addresses
from the IP header are used but only after being checked against the
authenticated "copies").

   > So please update the design security considerations!
   
   If you have exact text changes, please send them. 

=> I keep this message and I'll try to propose something.

Regards

[email protected]