RE: Security draft issue (4) - IPsec
"Caitlin Bestler" <[email protected]>
| Newsgroups | gmane.ietf.rddp |
|---|---|
| Message-ID | <[email protected]> |
[email protected] said: > Caitlin, > >> Until IPsec is mandatory-to-implement for IP hosts I see no >> justification for making it mandatory for RDDP endpoints. And >> of course if it were mandatory-to-implement for IP Hosts, RDDP >> would not have to implement it. > > IPsec is mandatory-to-implement for IPv6 hosts, FWIW. The IESG > will not approve standards-track RFCs that lack mandatory-to- > implement security measures, although it's possible to reference > measures that already exist elsewhere in the environment. > > If RDDP introduced no new risks above and beyond TCP or SCTP > over IPv4, then falling back to the security requirements of > those underlying protocols might be acceptable - I don't > believe this to be the case, though (i.e., there are new > RDDP-specific security risks). > > Thanks, > --David I do not see any RDDP specific vulnerabilities that are relevant to the use of IPsec. A non-RDDP application enables reception of peer messages into application buffers. Given the nature of non-RDDP LLPs, use of intermediate system buffering is likely. Once received, the Application judges the applicability of transport layer security to its needs. It may determine that the transport has provided sufficient authentication of the remote peer to allow acting upon the received messages without further validation, or it may decide to apply its own validation. So what changes with RDDP? Nothing, except that the intermediate system buffering is far less likely. That *improves* security, not worsens it. Whether or not IPsec is in use, the Application already has full control of which of its buffers are exposed, to what extent, and for how long. Procedures to precisely control that exposure are already documented in the security draft and are not dependent on the use of IPsec or other transport layer security. There are also several problems with mandating IPsec implemenetation. First, what is the meaning of the mandate when the RDDP implementation is cleanly layered over the LLP (or even when it is integrated with the LLP, but they are cleanly layered over IP)? Surely we are not going to require that an RDDP implementation refuse to use a valid TCP or IP stack because it lacks IPsec support. Secondly, we need to recognize that authentication and privacy can be fully achieved in many IP networks without any support for IPsec in the host through physical security, managed switches and in-network IPsec devices. In fact there are strong arguments why network implemented security is superior to host implemented security. Further, many RDDP deployments will be in precisely these sort of controlled environments. Lastly, requiring RDDP vendors to implement IPsec will in merely force mediocre implementations to be integrated and pre-empt the use of superior IPsec implemetnations that are not integrated. For all of these reasons, I strongly believe that RDDP should remain oblivious to LLP provided security, and merely use whatever is there. -- Caitlin Bestler http://asomi.com/