On 21/10/2012 04:01, Ted Lemon wrote: > On Oct 20, 2012, at 10:55 PM, "Tirumaleswar Reddy (tireddy)" > <[email protected]> wrote: >> Yes. In such Managed Networks, SLAAC is disabled and IPv6 addresses are only >> assigned using DHCPv6 server. Switches in such environments provide First >> Hop Security by gleaning DHCP/NDP messages and can make sure hosts are using >> the IPv6 addresses assigned by the DHCPv6 server only (Source Guard). With >> the technique in this draft only certain hosts will be permitted assignment >> of IA_TA and not for other hosts. > > That makes sense—thanks for clarifying!
It makes sense, but the draft doesn't explain that it is only intended for use in managed networks where the suppression of privacy is considered acceptable. I think this needs to be stated in the Introduction, and the issue of (loss of) privacy needs to be discussed in the Security Considerations. How will users know that temporary addressing has been disabled? Is there a risk of a rogue DHCPv6 relay switching off temporary addressing for hosts that really need it? Also, in the section > 3.2.1. Avoiding Excessive IP-Based Authentication it says: > When Address-based authentication is used, re- > authentication occurs for each address obtained by the host, which > can create a lot of authentication transactions. To reduce this > chatter, This doesn't convince me that the proposed feature is solving a real problem. "A lot of" and "chatter" are vague terms. Can you add something to suggest what size of a network would have a real performance problem as a result? Regards Brian Carpenter _______________________________________________ mif mailing list [email protected] https://www.ietf.org/mailman/listinfo/mif
