RES: RES: IPv6 tranisition issues

"Marcelo Barbosa Lima" <[email protected]> Mon, 6 Jan 2003 10:36:45 -0200
Newsgroups gmane.ietf.ngtrans
Message-ID <D49EA2F934FFAD45B337C07A9753C00E017F55DE@MAILSRV1.aquarius.cpqd.com.br>
 Pekka Savola,

   Sorry for my "market speak" but, of the RFC 2461:

   "Neighbor Discovery protocol packet exchanges can be authenticated
   using the IP Authentication Header [IPv6-AUTH].  A node SHOULD
   include an Authentication Header when sending Neighbor Discovery
   packets if a security association for use with the IP Authentication
   Header exists for the destination address.  The security associations
   may have been created through manual configuration or through the
   operation of some key management protocol.

   Received Authentication Headers in Neighbor Discovery packets MUST be
   verified for correctness and packets with incorrect authentication
   MUST be ignored.

   It SHOULD be possible for the system administrator to configure a
   node to ignore any Neighbor Discovery messages that are not
   authenticated using either the Authentication Header or Encapsulating
   Security Payload.  The configuration technique for this MUST be
   documented.  Such a switch SHOULD default to allowing unauthenticated
   messages.

   Confidentiality issues are addressed by the IP Security Architecture
   and the IP Encapsulating Security Payload documents [IPv6-SA, IPv6-
   ESP]."

  In a local enviroment is relatively more simple to create secutity associates between peers. Even PKI solution can be implemented. There are some purposes regarding authentication in Neighbor discovery protocol. I looked for a RFC/draft about it, but I did not find it. Please, who know where I can find it email me. If it is hard to implement, I think that it is not, because is more simple to establish SAs in local network.
Regards,

			Marcelo. 

-----Mensagem original-----
De: Pekka Savola [mailto:[email protected]]
Enviada em: segunda-feira, 6 de janeiro de 2003 10:10
Para: Marcelo Barbosa Lima
Cc: [email protected]; Thakur, Anand; [email protected];
[email protected]
Assunto: Re: RES: (ngtrans) IPv6 tranisition issues


On Mon, 6 Jan 2003, Marcelo Barbosa Lima wrote:
> >Yes, in a typing fury I forgot/missed the IPv6 solution for mobility.
> >IPv6 is streamlined and designed for mobility in mind. Again there are
> >the patches in IPv4, although riddled with triangular routing issues.
> >But then again is there anyone really into mobile IP? And I use NTT
> >DoCoMo and likes in Japan as examples for this and not a 'hotspot' cafe
> >answer on 802.11.
> >
> 
>   In IPv4, attacks against ARP protocol (mobile IPv4 trusts in ARP
> protocol) are easy to implment. DHCP can also be bypassed easily. So,
> neighbour protocol with AH is more secure solution. Regards,

Less market speak, more technology, please.

Securing the neighbor protocol with AH is _hard_.

Please check out SEND working group.

-- 
Pekka Savola                 "Tell me of difficulties surmounted,
Netcore Oy                   not those you stumble over and fall"
Systems. Networks. Security.  -- Robert Jordan: A Crown of Swords