| Newsgroups |
gmane.ietf.rddp |
| Message-ID |
<[email protected]> |
It appears that the option of allowing RDDP implementations
to only support one-shot STags is not acceptable, so I believe
the rough consensus of the RDDP WG is that all implementations
MUST support long-lived STags. Send any objections to the list.
Unfortunately, the following security alternative that Caitlin
proposes is not acceptable to the IESG:
> b) There are alternate forms of anti-spoofing that address
> the Security issues for applications not using the available
> tools just as well as IPsec does. Foremost of these would
> be use of IPsec within routers combined with managed
> switches.
In essence, if the RDDP protocols can reasonably be used in
situations that create security exposures (e.g., on the public
Internet), then the IESG requires that countermeasures to those
exposures be "MUST implement". At the London IETF in 2001, an
attempt was made in the IESG plenary to remove a similar "MUST
implement" requirement for IPsec for one of the IP Storage protocols
on roughly the above basis (if you want IPsec, use an external
IPsec gateway, but don't make it a protocol requirement). The
IESG shot this attempt down in flames. Unless one is a glutton
for punishment, I don't recommend repeating this experiment.
Given the resistance to a "MUST implement IPsec" requirement,
the only obvious remaining path forward is to design security
mechanisms into the RDDP protocols (i.e., solve the security
exposures created by RDDP headers with long-lived STags without
resorting to IPsec). To a first approximation, the security
mechanisms will have to be able to address the following:
If an attacker hijacks a transport connection and
attempts to make use of an existing STag, the attempt
will fail because <put details of security mechanism
here>.
I will need to talk to the security ADs about what the detailed
requirements are that will be acceptable, but I think it's safe
to assume that STag unpredictability will be part of them.
Comments?
Thanks,
--David
----------------------------------------------------
David L. Black, Senior Technologist
EMC Corporation, 176 South St., Hopkinton, MA 01748
+1 (508) 293-7953 FAX: +1 (508) 293-7786
[email protected] Mobile: +1 (978) 394-7754
----------------------------------------------------