On 21/10/2012 04:01, Ted Lemon wrote:
> On Oct 20, 2012, at 10:55 PM, "Tirumaleswar Reddy (tireddy)" 
> <[email protected]> wrote:
>> Yes. In such Managed Networks, SLAAC is disabled and IPv6 addresses are only 
>> assigned using DHCPv6 server. Switches in such environments provide First 
>> Hop Security by gleaning DHCP/NDP messages and can make sure hosts are using 
>> the IPv6 addresses assigned by the DHCPv6 server only (Source Guard). With 
>> the technique in this draft only certain hosts will be permitted assignment 
>> of IA_TA and not for other hosts. 
> 
> That makes sense—thanks for clarifying!

It makes sense, but the draft doesn't explain that it is only
intended for use in managed networks where the suppression of
privacy is considered acceptable. I think this needs to be stated
in the Introduction, and the issue of (loss of) privacy needs to
be discussed in the Security Considerations.

How will users know that temporary addressing has been disabled?

Is there a risk of a rogue DHCPv6 relay switching off temporary
addressing for hosts that really need it?

Also, in the section

> 3.2.1.  Avoiding Excessive IP-Based Authentication

it says:

>                      When Address-based authentication is used, re-
>    authentication occurs for each address obtained by the host, which
>    can create a lot of authentication transactions.  To reduce this
>    chatter,

This doesn't convince me that the proposed feature is solving a real
problem. "A lot of" and "chatter" are vague terms. Can you add something
to suggest what size of a network would have a real performance problem
as a result?

Regards
   Brian Carpenter


_______________________________________________
mif mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/mif

Reply via email to