Re: [DMM] RFC4283bis progress..

2015-07-14 Thread Templin, Fred L
Hi Sri, Reason for the X.509 certificate is that, in some environments, an attacker can spoof a DHCP Client Identifier and receive services that were intended for the authentic client. With X.509 certificate, the certificate holder has to sign its DHCP messages with its private key so the DHCP

Re: [DMM] RFC4283bis progress..

2015-07-14 Thread Brian Haberman
Hi Fred, On 7/14/15 10:54 AM, Templin, Fred L wrote: Hi Sri, Reason for the X.509 certificate is that, in some environments, an attacker can spoof a DHCP Client Identifier and receive services that were intended for the authentic client. With X.509 certificate, the certificate

Re: [DMM] RFC4283bis progress..

2015-07-14 Thread Templin, Fred L
Hi Brian, -Original Message- From: dmm [mailto:dmm-boun...@ietf.org] On Behalf Of Brian Haberman Sent: Tuesday, July 14, 2015 8:37 AM To: dmm@ietf.org Subject: Re: [DMM] RFC4283bis progress.. Hi Fred, On 7/14/15 10:54 AM, Templin, Fred L wrote: Hi Sri, Reason for the

Re: [DMM] RFC4283bis progress..

2015-07-14 Thread Brian Haberman
On 7/14/15 12:19 PM, Templin, Fred L wrote: Hi Brian, -Original Message- From: dmm [mailto:dmm-boun...@ietf.org] On Behalf Of Brian Haberman Sent: Tuesday, July 14, 2015 8:37 AM To: dmm@ietf.org Subject: Re: [DMM] RFC4283bis progress.. Hi Fred, On 7/14/15 10:54 AM, Templin,

Re: [DMM] RFC4283bis progress..

2015-07-14 Thread Sri Gundavelli (sgundave)
Brian/Fred, This is exactly what I was thinking. Conveying identity and validating identity are two different things. What is carried in NAI (RFC4283) is just un-authenticated identity. What is needed for validation is a protocol extension such as in RFC4285. Regards Sri On 7/14/15, 11:30 AM,

Re: [DMM] RFC4283bis progress..

2015-07-14 Thread Templin, Fred L
Hi Brian, -Original Message- From: dmm [mailto:dmm-boun...@ietf.org] On Behalf Of Brian Haberman Sent: Tuesday, July 14, 2015 11:31 AM To: dmm@ietf.org Subject: Re: [DMM] RFC4283bis progress.. On 7/14/15 12:19 PM, Templin, Fred L wrote: Hi Brian, -Original

[DMM] New Version Notification for draft-yan-dmm-hnprenum-02.txt

2015-07-14 Thread Z.W. Yan
Hi, all, Based on the comments we collected on-line and off-line, we updated the draft of HNP renumbering in PMIPv6. https://tools.ietf.org/html/draft-yan-dmm-hnprenum-02 Any comments from you are all welcome. Thanks. Zhiwei Yan ___ dmm mailing list

[DMM] DMM agenda update

2015-07-14 Thread Dapeng Liu
Hello all, We update the DMM agenda: https://datatracker.ietf.org/meeting/93/agenda/dmm/ Please send slides to chairs as soon as possible if you have presentation on the agenda. Thanks, -- Dapeng Jouni ___ dmm mailing list dmm@ietf.org

Re: [DMM] DMM agenda update

2015-07-14 Thread Jouni Korhonen
A note reminder to the WG.. the agenda is packed as you can see and has some bias to main WT topics. There's only 5 mins slack there. Plan your presentations accordingly. If you want answers from the WG for something do not spend time going through stuff that folks can read themselves -

Re: [DMM] RFC4283bis progress..

2015-07-14 Thread Jouni Korhonen
This is doable using Hash and URL of X.509 certificate used in IKEv2 certificate payloads. See RFC 7296 Section 3.6. That should fit into 254 bytes assuming the URL is not extra long. - Jouni 7/14/2015, 8:36 AM, Brian Haberman kirjoitti: Hi Fred, On 7/14/15 10:54 AM, Templin, Fred L