Re: New issue 18: Threat discussion
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote: Actually, let me rephrase: I do not want to imply that "transient pseudo-NAT" attack has no relevance for MOBIKE. MOBIKE is all about authenticated management of (change of) address. And "pseudo-NAT" is about malicious change of address. So there is definite relevance there. The issue is that problem can be manifested in several scenarios other than just IKE. => in my draft I talk about signaling protocols with two concrete examples, mobile IP (look at RFC 3519 security considerations) and IKE. IMHO MOBIKE is concerned both for itself and as a source of clarification for IKE in a mobile/multi-homed environment. It may make sense to either do a general solution (else where?) => there is an easy solution but obviously incompatible with NAT traversal. or if we do MOBIKE-specific solution, => I don't believe in a MOBIKE-specific solution. In fact, the current discussion is about the defense against "third party bombing" which includes "transient pseudo-NAT"/ we should let other affected working groups be made aware of it. => this is done for mobile IP and this is a bit late for IKE (in fact this is covered by the pki4ipsec profile in its default policies). But IMHO it will be good to include somewhere in a MOBIKE document a clarification about this attack, just in order to avoid unsafe misinterpretation of the IKEv2 address agility. Regards [email protected]