On Tue, 26 Jun 2001, Erik Nordmark wrote:

> > >Deprecate IPV6_V6ONLY, add IPV6_ACCEPTV4MAPPED option
> > >
> > >   Then the IPv6 sockets would have to be explicitly allowed to accept
> > >   IPv4 connections. So the programs that use the IPv6 centric way have
> > >   to be modified a bit, but the buggy implementations and the unworkable
> > >   one could be corrected without losing features. Just making
> > >   IPV6_V6ONLY default to on would have the same results.
> >
> >     I really love to see this happen (polarity change is enough).
> >     also, if IPv4 mapped address support becomes optional (explicitly)
> >     to OS implementers it would be much better.
>
> In hindsight I agree that the default should have been different - forcing
> applications to explicitly request use of IPv4-mapped addresses on AF_INET6
> sockets.
> But I suspect that folks have different opinions on the cost of changing
> the default at this point in time :-(

Another point here is security, especially if overloading mapped addresses
is allowed to continue (SIIT).

10 years ago all Unix vendors shipped about all services enabled by
default.  At some point people began to realize that it's an endless
battle if users/application writers must take full care of that.  So, wise
vendors have changed the default from "enable everything" to "enable
what's needed".  Some haven't gotten it yet, or depend too heavily on old
cruft, and are afraid to (possibly) break some customers who might
actually be running obscure_serviced.

I just hope we won't be doing the same mistake here.

-- 
Pekka Savola                 "Tell me of difficulties surmounted,
Netcore Oy                   not those you stumble over and fall"
Systems. Networks. Security.  -- Robert Jordan: A Crown of Swords


--------------------------------------------------------------------
IETF IPng Working Group Mailing List
IPng Home Page:                      http://playground.sun.com/ipng
FTP archive:                      ftp://playground.sun.com/pub/ipng
Direct all administrative requests to [EMAIL PROTECTED]
--------------------------------------------------------------------

Reply via email to