Security considerations...SEND interaction....IESG "discuss" item

Radia Perlman <[email protected]>
Newsgroups gmane.ietf.vrrp
Message-ID <[email protected]>
I guess I'll put on my security advisor hat and take off my cochair hat 
for this thread.

Sam Hartman brought up a good point, which is how might VRRP interact 
with SEND. (secure
neighbor discovery). The basic idea of SEND (from my memory) is that 
with IPv6 addresses, a
node can select the bottom 8 bytes of its address to be a hash of a 
public key, and then sign
ND advertisements using the private key.

So, one way I could imagine SEND impacting VRRP is that the routers 
would all have to know
the private key associated with the shared IP address, so that they 
could then do the ND advertisements
if they took over as master.

Sam specifically asked though whether there might actually be some use 
for authentication of VRRP
messages in the SEND case. And that's a good point. Otherwise, someone 
could prevent one
of the real guys from getting elected, impersonating a VRRP router in 
the election, whereas SEND would
have prevented them from answering ND queries. So it is possible in that 
case that if neighbor discovery
is being armored, that VRRP should be similarly armored.

I haven't thought about this a lot, but my inclination would be to have, 
in that case, the VRRP message
signed with the same mechanism, and with the same private key, as the 
IPv6 address key.

Is there anyone else who wants to think about this?

Radia


_______________________________________________
vrrp mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/vrrp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.