RE: Security draft issue (4) - IPsec

"Caitlin Bestler" <[email protected]>
Newsgroups gmane.ietf.rddp
Message-ID <[email protected]>
[email protected] said:
> Caitlin,
>
>> Until IPsec is mandatory-to-implement for IP hosts I see no
>> justification for making it mandatory for RDDP endpoints. And
>> of course if it were mandatory-to-implement for IP Hosts, RDDP
>> would not have to implement it.
>
> IPsec is mandatory-to-implement for IPv6 hosts, FWIW.  The IESG
> will not approve standards-track RFCs that lack mandatory-to-
> implement security measures, although it's possible to reference
> measures that already exist elsewhere in the environment.
>
> If RDDP introduced no new risks above and beyond TCP or SCTP
> over IPv4, then falling back to the security requirements of
> those underlying protocols might be acceptable - I don't
> believe this to be the case, though (i.e., there are new
> RDDP-specific security risks).
>
> Thanks,
> --David

I do not see any RDDP specific vulnerabilities that are relevant
to the use of IPsec.

A non-RDDP application enables reception of peer messages into
application buffers. Given the nature of non-RDDP LLPs, use
of intermediate system buffering is likely.

Once received, the Application judges the applicability of
transport layer security to its needs. It may determine that
the transport has provided sufficient authentication of the
remote peer to allow acting upon the received messages without
further validation, or it may decide to apply its own validation.

So what changes with RDDP?

Nothing, except that the intermediate system buffering is
far less likely. That *improves* security, not worsens it.

Whether or not IPsec is in use, the Application already
has full control of which of its buffers are exposed,
to what extent, and for how long. Procedures to precisely
control that exposure are already documented in the security
draft and are not dependent on the use of IPsec or other
transport layer security.


There are also several problems with mandating IPsec
implemenetation.

First, what is the meaning of the mandate when the RDDP
implementation is cleanly layered over the LLP (or
even when it is integrated with the LLP, but they
are cleanly layered over IP)?

Surely we are not going to require that an RDDP implementation
refuse to use a valid TCP or IP stack because it lacks
IPsec support.

Secondly, we need to recognize that authentication and
privacy can be fully achieved in many IP networks without
any support for IPsec in the host through physical security,
managed switches and in-network IPsec devices. In fact there
are strong arguments why network implemented security is
superior to host implemented security.

Further, many RDDP deployments will be in precisely these
sort of controlled environments.

Lastly, requiring RDDP vendors to implement IPsec will
in merely force mediocre implementations to be integrated
and pre-empt the use of superior IPsec implemetnations that
are not integrated.

For all of these reasons, I strongly believe that RDDP should
remain oblivious to LLP provided security, and merely use
whatever is there.



--
Caitlin Bestler
http://asomi.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.