DDP/RDMAP Applicability
Derek Atkins <[email protected]> Wed, 19 Apr 2006 13:12:47 -0400
| Newsgroups | gmane.ietf.rddp |
|---|---|
| Message-ID | <[email protected]> |
I was asked to review the DDP/RDMAP specifications. Here are my comments on draft-ietf-rddp-applicability-05.txt -derek ---- Spelling error in Abstract: It comparese and contrasts the different transport options over IP should be: It compares ... ---- Spelling/typographical errors in section 4, Tagged Messages: Tagged messages standardizes direct placemtn of data without per- should be: Tagged messages standardizes direct placement of data without per- -- DDP provides a standardized\ 'packing list' which can be interpreted should be: DDP provides a standardized 'packing list' which can be interpreted ---- Typo in 6.9.2. RDMA-Conditional Session Establishment: In key difference is that with SCTP the determination as to whether should (probably) be: One key difference ... ---- ---- Section 6.6 : Data Integrity Implications CRC32 helps protect against accidental data corruption, but not intensional data corruption. An attacker could easily intentionally corrupt the data and a CRC32 cannot detect that. I recommend some stronger wording that an active attacker could easily subvert the CRC32, or at least additional text that explains that CRC32 only protects against accidental data corruption and not intensional data corruption. ---- Section 9 : Security considerations The discussion of the steering tag doesn't discuss what information is exposed, or how guessable these tags could be. What's the implication of a "peer" guessing at random STags? Could I get data that I shouldn't have access to? Are these STags tied to a particular peer session, and if so how? -- There's no discussion of peer authentication. How do I know who I'm talking to and how do I authenticate and authorize their RDMA access? ---- Section 9.2 : Tagged Buffer Exposure This section does not go into enough detail of what can happen if an attacker can insert random (or worse, non random!) data into arbitrary buffers. We've got so many buffer overrun attacks. Imagine what could happen if an attacker didn't need to overrun a buffer but could co-opt the RDMA and insert arbitrary data into buffers directly. > ---------- Forwarded message ---------- > Date: Wed, 05 Apr 2006 16:49:04 -0400 > From: The IESG <[email protected]> > To: IETF-Announce <[email protected]> > Cc: [email protected] > Subject: Last Call: 'DDP/RDMAP Security' to Proposed Standard > > The IESG has received a request from the Remote Direct Data Placement WG to > consider the following documents: > > - 'DDP/RDMAP Security ' > <draft-ietf-rddp-security-08.txt> as a Proposed Standard > - 'Applicability of Remote Direct Memory Access Protocol (RDMA) and Direct Data > Placement (DDP) ' > <draft-ietf-rddp-applicability-05.txt> as an Informational RFC > > The IESG plans to make a decision in the next few weeks, and solicits > final comments on this action. Please send any comments to the > [email protected] or [email protected] mailing lists by 2006-04-19. > > The file can be obtained via > http://www.ietf.org/internet-drafts/draft-ietf-rddp-security-08.txt > http://www.ietf.org/internet-drafts/draft-ietf-rddp-applicability-05.txt > > > _______________________________________________ > IETF-Announce mailing list > [email protected] > https://www1.ietf.org/mailman/listinfo/ietf-announce > > > > -- Derek Atkins 617-623-3745 [email protected] www.ihtfp.com Computer and Internet Security Consultant