Re: WGLC on the design draft

Tero Kivinen <[email protected]> Thu, 5 Jan 2006 14:58:35 +0200
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Francis Dupont writes:
>  In your previous mail you wrote:
> 
>    > I strongly disagree: not authenticate the IP addresses just leaves
>    > the protocol vulnerable to attacks modifying them, i.e., you can
>    > establish the IKE SA and IPsec SAs with a bad address (cf what I call
>    
>    The IP addresses in the IP header are not authenticated. That is state
>    of fact.
>    
> => yes but the protocol document addresses this issue so I simply suggest
> to put the same text into the design document.

This document is not meant to be limited to the specific protocol, it
tries to be more generic one. The protocol document provided solution
to that and the text describing that solution belongs to that
document. 

> => strictly you're right but this is not how it is implemented (as the
> options are not copies but hashes of the IP addresses the IP addresses
> from the IP header are used but only after being checked against the
> authenticated "copies").

Actually current draft-ietf-mobike-protocol-07 do copy the addresses
and ports from the IP header to the NO_NATS_ALLOWED payload (without
any hashes or similar). It will return error
(UNEXPECTEED_NAT_DETECTED) if those do not match. But as these are
things that can change so it is better that the generic design
document does not mention those, but simply mentions that there is
problem, and the actual protocol document needs to take care of them.

We do now have text:
----------------------------------------------------------------------
   See Security considerations section of [I-D.ietf-mobike-protocol] for
   more information about security considerations of the actual
   protocol.
----------------------------------------------------------------------
at the end of security considerations section.
-- 
[email protected]