Fernando Gont
Tue, 19 Apr 2005 13:08:42 -0700
At 14:35 13/04/2005 -0500, [EMAIL PROTECTED] wrote:
===
6. As the ICMP messages are passed to the upper-layer
processes, it is possible to perform attacks on the
upper layer protocols (e.g., TCP) with ICMP [TCP-attack].
Protecting the upper layer with IPsec mitigates this
problem. If not protected by IPsec, it is recommended
for the upper layers to perform some form of validation
of ICMP messages (using the information contained in
the payload of the ICMP) before action upon them. The
actual validation checks are specific to the upper
layers and are out of the scope of this spec.
===
This is great.
A few comments on this text:
* The text says
" If not protected by IPsec, it is recommended
for the upper layers to perform some form of validation
of ICMP messages (using the information contained in
the payload of the ICMP) before action upon them"* s/action/acting/
* s/of the ICMP/of the ICMP message/
If you agree with these changes, the text would look like: === 6. As the ICMP messages are passed to the upper-layer processes, it is possible to perform attacks on the upper layer protocols (e.g., TCP) with ICMP [TCP-attack]. It is recommended for the upper layers to perform some form of validation of ICMP messages (using the information contained in the payload of the ICMP message) before acting upon them. The actual validation checks are specific to the upper layers and are out of the scope of this spec. Protecting the upper layer with IPsec mitigates these attacks. ===
The third point that you raise about the hard and the soft errors, I am not sure what to do. Do we already have a resolution for TCP that - it should not consider any of the ICMP messages as hard errors ? Or - it should perform some checks and then consider them as hard and soft according to RFC 1122 ? or - something else ?
Could you suggest what specific text we should add to ICMPv6 to cover the issue of hard and soft errors ?
Yea. How about this:
Kindest regards,
-- Fernando Gont e-mail: [EMAIL PROTECTED] || [EMAIL PROTECTED]
-------------------------------------------------------------------- IETF IPv6 working group mailing list ipv6@ietf.org Administrative Requests: https://www1.ietf.org/mailman/listinfo/ipv6 --------------------------------------------------------------------