Re: WGLC on the design draft
Tero Kivinen <[email protected]> Thu, 5 Jan 2006 14:58:35 +0200
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Francis Dupont writes: > In your previous mail you wrote: > > > I strongly disagree: not authenticate the IP addresses just leaves > > the protocol vulnerable to attacks modifying them, i.e., you can > > establish the IKE SA and IPsec SAs with a bad address (cf what I call > > The IP addresses in the IP header are not authenticated. That is state > of fact. > > => yes but the protocol document addresses this issue so I simply suggest > to put the same text into the design document. This document is not meant to be limited to the specific protocol, it tries to be more generic one. The protocol document provided solution to that and the text describing that solution belongs to that document. > => strictly you're right but this is not how it is implemented (as the > options are not copies but hashes of the IP addresses the IP addresses > from the IP header are used but only after being checked against the > authenticated "copies"). Actually current draft-ietf-mobike-protocol-07 do copy the addresses and ports from the IP header to the NO_NATS_ALLOWED payload (without any hashes or similar). It will return error (UNEXPECTEED_NAT_DETECTED) if those do not match. But as these are things that can change so it is better that the generic design document does not mention those, but simply mentions that there is problem, and the actual protocol document needs to take care of them. We do now have text: ---------------------------------------------------------------------- See Security considerations section of [I-D.ietf-mobike-protocol] for more information about security considerations of the actual protocol. ---------------------------------------------------------------------- at the end of security considerations section. -- [email protected]