Security considerations...SEND interaction....IESG "discuss" item
Radia Perlman <[email protected]>
| Newsgroups | gmane.ietf.vrrp |
|---|---|
| Message-ID | <[email protected]> |
I guess I'll put on my security advisor hat and take off my cochair hat for this thread. Sam Hartman brought up a good point, which is how might VRRP interact with SEND. (secure neighbor discovery). The basic idea of SEND (from my memory) is that with IPv6 addresses, a node can select the bottom 8 bytes of its address to be a hash of a public key, and then sign ND advertisements using the private key. So, one way I could imagine SEND impacting VRRP is that the routers would all have to know the private key associated with the shared IP address, so that they could then do the ND advertisements if they took over as master. Sam specifically asked though whether there might actually be some use for authentication of VRRP messages in the SEND case. And that's a good point. Otherwise, someone could prevent one of the real guys from getting elected, impersonating a VRRP router in the election, whereas SEND would have prevented them from answering ND queries. So it is possible in that case that if neighbor discovery is being armored, that VRRP should be similarly armored. I haven't thought about this a lot, but my inclination would be to have, in that case, the VRRP message signed with the same mechanism, and with the same private key, as the IPv6 address key. Is there anyone else who wants to think about this? Radia _______________________________________________ vrrp mailing list [email protected] https://www1.ietf.org/mailman/listinfo/vrrp