Re: WGLC on the design draft
Francis Dupont <[email protected]> Thu, 05 Jan 2006 23:19:59 +0100
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote:
> => yes but the protocol document addresses this issue so I simply suggest
> to put the same text into the design document.
This document is not meant to be limited to the specific protocol, it
tries to be more generic one. The protocol document provided solution
to that and the text describing that solution belongs to that
document.
> => strictly you're right but this is not how it is implemented (as the
> options are not copies but hashes of the IP addresses the IP addresses
> from the IP header are used but only after being checked against the
> authenticated "copies").
Actually current draft-ietf-mobike-protocol-07 do copy the addresses
and ports from the IP header to the NO_NATS_ALLOWED payload (without
any hashes or similar).
=> only in the NAT prevention case, in the NAT detection case a hash
is used in order to hide the real address.
It will return error
(UNEXPECTEED_NAT_DETECTED) if those do not match. But as these are
things that can change so it is better that the generic design
document does not mention those, but simply mentions that there is
problem, and the actual protocol document needs to take care of them.
=> we agree.
We do now have text:
^^^
----------------------------------------------------------------------
See Security considerations section of [I-D.ietf-mobike-protocol] for
more information about security considerations of the actual
protocol.
----------------------------------------------------------------------
at the end of security considerations section.
=> this is a fine way to have to present problems but not the solutions
(so to keep what has to be in the document).
Regards
[email protected]