Re: Future of the PPP WG

Glen Zorn <[email protected]> Sat, 10 Sep 2011 12:30:50 +0700
Newsgroups gmane.ietf.pppext
Message-ID <[email protected]>
On 9/10/2011 1:18 AM, Donald Eastlake wrote:

...

>>> In the process of producing RFC 6361, it became very apparent that the
>>> PPP security RFCs, such as they are, meet few, if any, modern IETF
>>> security guidelines.
>>
>> Would these be realistic guidelines (such as RFC 3552 (but do you
>> consider that 'modern')) or pie-in-the-sky "in my dream world this is
>> how it would work" guidelines (like RFC 4962)?
> 
> I should think the PPPEXT WG would decided which guidelines, subject
> to the constrains of getting documents through the IETF process :-)
> 
>>> I believe that there should be an update of PPP
>>> security or, if an effort to update them fails for some reason, then
>>> at least old / inadequate / unimplemented PPP security RFCs should be
>>> declared historic.
>>
>> Do you have a list of said RFCs?
> 
> I don't think it is complete but how about the following to start with:
> 
> "The PPP Encryption Control Protocol (ECP)",
>                RFC 1968, June 1996.
> "PPP Challenge Handshake Authentication
>                Protocol (CHAP)", RFC 1994, August 1996.
> "The PPP Triple-DES Encryption Protocol (3DESE)", RFC 2420, September 1998.
> 

OK, I guess the crux of my previous question (which I apparently did not
express well) is whether or not the proposed updates are solely or at
least primarily editorial in nature (e.g., bringing the Security
Considerations section into line with the recommendations of RFC 3552).
 Of the documents you mention, I suspect that RFC 1968 & RFC 2420 could
probably be changed any way we want to, since AFAIK there are no actual
deployments of either (I request correction!) but we can't go changing
the way that CHAP works.

...
_______________________________________________
Pppext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pppext