Re: Non-unique ENRP identifier?
Qiaobing Xie <[email protected]>
| Newsgroups | gmane.ietf.rserpool |
|---|---|
| Message-ID | <[email protected]> |
Thomas, I remember that this ID collision problem was discussed extensively in the past (both at past meetings and on the list). The conclusion was that the probability of its happening was so low that it's not really worthwhile to fix it. And I do not view this as a secu threat since it is too ineffective for an attacker to explore (i.e., why he or she wants to choose such an attack method, knowing the probability of success is just 1 out of 4 billion tries?). regards, -Qiaobing Thomas Dreibholz wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi all, > > section 4.2.2 of the ENRP draft defines that the ENRP identifier must be "as > unique as possible in the operational scope" and recommends a random number. > But what happens when two nameservers choose the same number? Although the > probability for choosing the same random 32-bit numbers is low (an attacker > may increase it), this may happen. And in this case, it will cause at least > severe problems for the takeover procedure. If one of the equal-numbered NSs > fails, the other one will answer a PEER_INIT_TAKEOVER with a PEER_PRESENCE > and therefore abort the takeover. > > Best regards > - -- > ======================================================================= > Dipl.-Inform. Thomas Dreibholz > > University of Essen, Room ES210 > Inst. for Experimental Mathematics Ellernstraße 29 > Computer Networking Technology Group D-45326 Essen/Germany > - ----------------------------------------------------------------------- > E-Mail: [email protected] > Homepage: http://www.exp-math.uni-essen.de/~dreibh > ======================================================================= > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.2.2 (GNU/Linux) > > iD8DBQE/dBA332BbsHYPLWURAiZAAKCHEHPi4Cj4OYked6yNqePD48gq2ACgp1TO > 4VJOctPSnu7kdA/i/zrtr6c= > =dkR5 > -----END PGP SIGNATURE----- > > _______________________________________________ > rserpool mailing list > [email protected] > https://www1.ietf.org/mailman/listinfo/rserpool