Hi, This mail goes to the ipfix and syslog mailing lists in order to summarize the common issues regarding DTLS.
IPFIX specifies support of DTLS as mandatory for transport over UDP and SCTP in RFC5101. In SYSLOG, it is intended to standardize DTLS for transport over UDP. In IPFIX, we have a first implementation of IPFIX-over-DTLS/UDP, and we will have a first implementation of IPFIX-over-DTLS/SCTP very soon. During this implementation effort, we found that the current specification of DTLS/UDP has a severe flaw when used with unidirectional protocols (like IPFIX): The sender cannot recognize if the receiver has crashed and lost the DTLS state. We discuss this issue in a draft: http://tools.ietf.org/html/draft-mentz-ipfix-dtls-recommendations-00 http://www.ietf.org/proceedings/75/slides/ipfix-6.pdf I've had a look at draft-feng-syslog-transport-dtls-01 and draft-petch-gerhards-syslog-transport-dtls-02. It seems that this problem has not yet been covered, although the problem should be the same for SYSLOG. As a solution, the DTLS Heartbeat Extension has been proposed very recently: http://tools.ietf.org/html/draft-seggelmann-tls-dtls-heartbeat-00 A feature patch for OpenSSL is available: http://sctp.fh-muenster.de/dtls-patches.html#features So, I think that we should support this standardization initiative as it solves our problem. For IPFIX and SYSLOG over DTLS/UDP, we then can specify that the DTLS Heartbeat Extension MUST be implemented. Dan suggested to have a single document solving the DTLS issues regarding unidirectional protocols. I think that such a document is not needed if we have DTLS Heartbeat Extension. Regards, Gerhard -- Dipl.-Ing. Gerhard Münz Chair for Network Architectures and Services (I8) Department of Informatics Technische Universität München Boltzmannstr. 3, 85748 Garching bei München, Germany Phone: +49 89 289-18008 Fax: +49 89 289-18033 E-mail: [email protected] WWW: http://www.net.in.tum.de/~muenz
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ Syslog mailing list [email protected] https://www.ietf.org/mailman/listinfo/syslog
