
From nobody Sat May 10 20:12:23 2014
Return-Path: <kk.chittimaneni@gmail.com>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1BD121A016A for <opsec@ietfa.amsl.com>; Sat, 10 May 2014 20:12:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.1
X-Spam-Level: 
X-Spam-Status: No, score=-0.1 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZW9z-3PDnb5j for <opsec@ietfa.amsl.com>; Sat, 10 May 2014 20:12:20 -0700 (PDT)
Received: from mail-yh0-x22e.google.com (mail-yh0-x22e.google.com [IPv6:2607:f8b0:4002:c01::22e]) by ietfa.amsl.com (Postfix) with ESMTP id 13D0E1A026F for <opsec@ietf.org>; Sat, 10 May 2014 20:12:19 -0700 (PDT)
Received: by mail-yh0-f46.google.com with SMTP id 29so5211218yhl.5 for <opsec@ietf.org>; Sat, 10 May 2014 20:12:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:date:message-id:subject:from:to:content-type; bh=1rFkWt1tL1RhVqArqKVF7zq5Cvqr7Eb5+h69hrcuesE=; b=zW/QNzbe4XAZz/QPNzFiDCiOmwb2LN7R3F8hU3EFAdW3pIvbug+PvfCwZbpnUWHyjt H1tDl6Mq8o3EldYRgHF8S9IwO+ZC/bleAA+5dbQ9mLoxLzZCj6AzDb4u4zjLvVLhTBsR 8+ALLMrxsHX8D+QGIotFv72KnT2d8nVYzEOWP5hBCJOmW8G+PvrGhw3S5cuCkWP0c88L 4TgRDBHGMkufunWSOo04ZWmG/valjzDkrA8Dv/gG77qBErSpQiwgkgBUc81HUgo6nzoc luM7xmNXblIJ6zKhpjzbmPnvuSvK4AiuOKigARete6eK9nqXLZo6n9LFFMcOATlUJsLY hOQQ==
MIME-Version: 1.0
X-Received: by 10.236.36.45 with SMTP id v33mr22909677yha.129.1399777934593; Sat, 10 May 2014 20:12:14 -0700 (PDT)
Received: by 10.170.156.87 with HTTP; Sat, 10 May 2014 20:12:14 -0700 (PDT)
Date: Sat, 10 May 2014 20:12:14 -0700
Message-ID: <CA+iP7bXkJHgw6W_+q7vgFFf6EgNxWuDB37NSxrLrC6+YScHirg@mail.gmail.com>
From: KK Chittimaneni <kk.chittimaneni@gmail.com>
To: opsec@ietf.org
Content-Type: multipart/alternative; boundary=089e0160bc688e50bc04f91732c4
Archived-At: http://mailarchive.ietf.org/arch/msg/opsec/FpOLbyrNW0Fzzdm-UvYvLVX1dmA
Subject: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 11 May 2014 03:12:22 -0000

--089e0160bc688e50bc04f91732c4
Content-Type: text/plain; charset=UTF-8

Dear Opsec WG,

The WGLC for this draft technically ended last month with just one response
received. Not enough to move forward.

The co-chairs chatted about this and noted that there was a lot more
support for this doc during earlier stages. Given that, we'd like to give
the WG a bit more time to review this and extend the LC to the 24th of May.
Ideally, we'd like to get at least two volunteers who could do a thorough
review of this doc and post their comments to the list.

The draft is available here:
https://datatracker.ietf.org/doc/draft-ietf-opsec-dhcpv6-shield/

<https://datatracker.ietf.org/doc/draft-ietf-opsec-ip-options-filtering/>
Please read it now and report to the list whether you support publication
or not. Insufficient responses will be taken as an indication of lack of
interest and we'll stop from proceeding further.

Regards,
KK (as Opsec WG co-chair)

--089e0160bc688e50bc04f91732c4
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Dear Opsec WG,<br><br></div><div>The WGLC for this dr=
aft technically ended last month with just one response received. Not enoug=
h to move forward.<br><br>The co-chairs chatted about this and noted that t=
here was a lot more support for this doc during earlier stages. Given that,=
 we&#39;d like to give the WG a bit more time to review this and extend the=
 LC to the 24th of May. Ideally, we&#39;d like to get at least two voluntee=
rs who could do a thorough review of this doc and post their comments to th=
e list.<br>
<br><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0=
pt"><span style=3D"font-size:13px;font-family:Arial;vertical-align:baseline=
">The draft is available here:=C2=A0<a href=3D"https://datatracker.ietf.org=
/doc/draft-ietf-opsec-dhcpv6-shield/" target=3D"_blank">https://datatracker=
.ietf.org/doc/draft-ietf-opsec-dhcpv6-shield/</a></span></p>


<br><a href=3D"https://datatracker.ietf.org/doc/draft-ietf-opsec-ip-options=
-filtering/" style=3D"text-decoration:none" target=3D"_blank"><span style=
=3D"font-size:13px;font-family:Arial;text-decoration:underline;vertical-ali=
gn:baseline"></span></a></div>
<div>Please read it now and report to the list whether you support publicat=
ion or not. Insufficient responses will be taken as an indication of lack o=
f interest and we&#39;ll stop from proceeding further.<br><br></div><div>
Regards,<br></div><div>KK (as Opsec WG co-chair)<br></div></div>

--089e0160bc688e50bc04f91732c4--


From nobody Mon May 12 06:09:47 2014
Return-Path: <evyncke@cisco.com>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AEFFE1A06FA for <opsec@ietfa.amsl.com>; Mon, 12 May 2014 06:09:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.151
X-Spam-Level: 
X-Spam-Status: No, score=-10.151 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U4eW03ZYVg1v for <opsec@ietfa.amsl.com>; Mon, 12 May 2014 06:09:42 -0700 (PDT)
Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) by ietfa.amsl.com (Postfix) with ESMTP id 0A7331A031E for <opsec@ietf.org>; Mon, 12 May 2014 06:09:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=9034; q=dns/txt; s=iport; t=1399900176; x=1401109776; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=khfn0VVsUTpUtwzW7g2/Ikq5atSgwz14PjUSEhV4nlw=; b=VIN3T/T7LDNmHlwvXDB9N81tT4Oox3CHvWVyDzZk7gnFqrRNAJdBuQO9 pbBlKe/3mefZFAZXS3LLtTGyH3DL2EQ20DlBCbWNJkRhNoLZM3d2pBSXH q9DrY/mxxrHH04inazg9bg4rbwVI1mcu4lNfbIAC6AOH/UXn/AlYfaCt1 8=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AmwFAL3HcFOtJV2Z/2dsb2JhbABZgkJET1jFawGBFhZ0giUBAQEEdAUQAgEIEQMBAigHIREUCQgCBAENBYgtAxENyFANhh8TBIw7ggYNBAeEQASXVoFyjR+FaIM2gi8
X-IronPort-AV: E=Sophos;i="4.97,1035,1389744000";  d="scan'208,217";a="43048723"
Received: from rcdn-core-2.cisco.com ([173.37.93.153]) by alln-iport-3.cisco.com with ESMTP; 12 May 2014 13:09:34 +0000
Received: from xhc-rcd-x02.cisco.com (xhc-rcd-x02.cisco.com [173.37.183.76]) by rcdn-core-2.cisco.com (8.14.5/8.14.5) with ESMTP id s4CD9Yxf012619 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 12 May 2014 13:09:34 GMT
Received: from xmb-aln-x02.cisco.com ([169.254.5.198]) by xhc-rcd-x02.cisco.com ([173.37.183.76]) with mapi id 14.03.0123.003; Mon, 12 May 2014 08:09:34 -0500
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: KK Chittimaneni <kk.chittimaneni@gmail.com>, "opsec@ietf.org" <opsec@ietf.org>
Thread-Topic: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
Thread-Index: AQHPbMbYfZxAQufNXkuwA/o7IiWXMps9Yp8A
Date: Mon, 12 May 2014 13:09:33 +0000
Message-ID: <CF969129.1AC75%evyncke@cisco.com>
References: <CA+iP7bXkJHgw6W_+q7vgFFf6EgNxWuDB37NSxrLrC6+YScHirg@mail.gmail.com>
In-Reply-To: <CA+iP7bXkJHgw6W_+q7vgFFf6EgNxWuDB37NSxrLrC6+YScHirg@mail.gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.4.1.140326
x-originating-ip: [10.55.185.75]
Content-Type: multipart/alternative; boundary="_000_CF9691291AC75evynckeciscocom_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/opsec/mlylNW6L5QK2jEy3Bc8twZWcCUo
Cc: Fernando Gont <fgont@si6networks.com>
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 May 2014 13:09:45 -0000

--_000_CF9691291AC75evynckeciscocom_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

KK, Gunter, Fernando & Will,

I have reviewed the document and here are my comments (some cosmetic):

  *   section 1: "on a specified port of the layer-2 device" =3D> "on speci=
fic port(s) of the layer-2 device" (plural form)
  *   Section 1: "Only those ports to which a DHCPv6 server" =3D> "Only tho=
se ports to which a DHCPv6 server or relay" (relays should be allowed as we=
ll)
  *   Section 3: not sure whether it is relevant here, this is well-known a=
nd accepted terminology, I am always uneasy when information is duplicated =
as it is an open door for inconsistency
  *   Section 3: should define what a 'DHCP shield device' is
  *   Section 5: I do not agree with point 1) if the specific platform cann=
ot handle a long ext header chain, it should be allowed to drop the packet =
(the MUST NOT should be SHOULD NOT or even a MAY =97 reversing the proposed=
 policy). Of course, such platforms cannot claim compatibility with DHCP-sh=
ield
  *   Section 5: "SHOULD be logged in an implementation-specific manner as =
security fault" =3D> "security alert" or "security event"
  *   Section 7: the whole I-D is only handling the physical/wired switched=
 case while in the introduction it is stated to be 'broadcast network'. The=
 security section and/or introduction should mention this.
  *   Section 7: should also mention other DHCP related threats? Such as Do=
S attack against DHCP servers? Amplification/reflection attacks? Of course,=
 the mitigation techniques are out of scope, but, I think that the threats =
should be mentioned
  *   Add a reference to SAVI-DHCP ?

Else, good document, pretty much like the well-known rogue DHCPv4

-=E9ric

From: Kiran Kumar Chittimaneni <kk.chittimaneni@gmail.com<mailto:kk.chittim=
aneni@gmail.com>>
Date: dimanche 11 mai 2014 05:12
To: "opsec@ietf.org<mailto:opsec@ietf.org>" <opsec@ietf.org<mailto:opsec@ie=
tf.org>>
Subject: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Dear Opsec WG,

The WGLC for this draft technically ended last month with just one response=
 received. Not enough to move forward.

The co-chairs chatted about this and noted that there was a lot more suppor=
t for this doc during earlier stages. Given that, we'd like to give the WG =
a bit more time to review this and extend the LC to the 24th of May. Ideall=
y, we'd like to get at least two volunteers who could do a thorough review =
of this doc and post their comments to the list.


The draft is available here: https://datatracker.ietf.org/doc/draft-ietf-op=
sec-dhcpv6-shield/

<https://datatracker.ietf.org/doc/draft-ietf-opsec-ip-options-filtering/>
Please read it now and report to the list whether you support publication o=
r not. Insufficient responses will be taken as an indication of lack of int=
erest and we'll stop from proceeding further.

Regards,
KK (as Opsec WG co-chair)

--_000_CF9691291AC75evynckeciscocom_
Content-Type: text/html; charset="Windows-1252"
Content-ID: <43180C2C8310B24AAC381B31D6D073FB@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-lin=
e-break: after-white-space; ">
<div style=3D"color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-s=
ize: 14px; ">
KK, Gunter, Fernando &amp; Will,</div>
<div style=3D"color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-s=
ize: 14px; ">
<br>
</div>
<div style=3D"color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-s=
ize: 14px; ">
I have reviewed the document and here are my comments (some cosmetic):</div=
>
<ul>
<li style=3D"color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-si=
ze: 14px; ">
section 1: &quot;<span style=3D"font-size: 1em; ">on a specified port of th=
e layer-2 device&quot; =3D&gt; &quot;</span><span style=3D"font-size: 1em; =
">on specific port(s) of the layer-2 device&quot; (plural form)</span></li>=
<li><font face=3D"Calibri,sans-serif">S<span style=3D"font-size: 1em;">ecti=
on 1: &quot;</span></font><span style=3D"font-size: 1em; ">Only those ports=
 to which a DHCPv6 server&quot; =3D&gt; &quot;</span><span style=3D"font-si=
ze: 1em; ">Only those ports to which a DHCPv6 server or relay&quot;
 (relays should be allowed as well)</span></li><li><span style=3D"color: rg=
b(0, 0, 0); font-family: Calibri; font-size: 14px; font-style: normal; font=
-weight: normal; text-decoration: none; ">Section 3: not sure whether it is=
 relevant here, this is well-known and accepted terminology, I am always un=
easy when
 information is duplicated as it is an open door for inconsistency</span></=
li><li>Section 3: should define what a 'DHCP shield device' is</li><li>Sect=
ion 5: I do not agree with point 1) if the specific platform cannot handle =
a long ext header chain, it should be allowed to drop the packet (the MUST =
NOT should be SHOULD NOT or even a MAY =97 reversing the proposed policy). =
Of course, such platforms
 cannot claim compatibility with DHCP-shield</li><li>Section 5: &quot;<span=
 style=3D"font-size: 1em; ">SHOULD be logged in an implementation-specific =
manner as
</span><span style=3D"font-size: 1em; ">security fault&quot; =3D&gt; &quot;=
security alert&quot; or &quot;security event&quot;</span></li><li>Section 7=
: the&nbsp;whole&nbsp;I-D is only handling the physical/wired switched case=
 while in the introduction it is stated to be 'broadcast network'. The secu=
rity section and/or introduction should mention this.</li><li>Section 7: sh=
ould also mention other DHCP related threats? Such as DoS attack against DH=
CP servers? Amplification/reflection attacks? Of course, the mitigation tec=
hniques are out of scope, but, I think that the threats should be mentioned=
</li><li>Add a reference to SAVI-DHCP ?</li></ul>
<div>Else, good document, pretty much like the well-known rogue DHCPv4</div=
>
<div><br>
</div>
<div>-=E9ric</div>
<div style=3D"color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-s=
ize: 14px; ">
<br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION" style=3D"color: rgb(0, 0, 0); font-family=
: Calibri, sans-serif; font-size: 14px; ">
<div style=3D"font-family:Calibri; font-size:11pt; text-align:left; color:b=
lack; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM:=
 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;=
 BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style=3D"font-weight:bold">From: </span>Kiran Kumar Chittimaneni &lt;=
<a href=3D"mailto:kk.chittimaneni@gmail.com">kk.chittimaneni@gmail.com</a>&=
gt;<br>
<span style=3D"font-weight:bold">Date: </span>dimanche 11 mai 2014 05:12<br=
>
<span style=3D"font-weight:bold">To: </span>&quot;<a href=3D"mailto:opsec@i=
etf.org">opsec@ietf.org</a>&quot; &lt;<a href=3D"mailto:opsec@ietf.org">ops=
ec@ietf.org</a>&gt;<br>
<span style=3D"font-weight:bold">Subject: </span>[OPSEC] Progressing draft-=
ietf-opsec-dhcpv6-shield<br>
</div>
<div><br>
</div>
<blockquote id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style=3D"BORDER-LEFT:=
 #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div>
<div>
<div dir=3D"ltr">
<div>Dear Opsec WG,<br>
<br>
</div>
<div>The WGLC for this draft technically ended last month with just one res=
ponse received. Not enough to move forward.<br>
<br>
The co-chairs chatted about this and noted that there was a lot more suppor=
t for this doc during earlier stages. Given that, we'd like to give the WG =
a bit more time to review this and extend the LC to the 24th of May. Ideall=
y, we'd like to get at least two
 volunteers who could do a thorough review of this doc and post their comme=
nts to the list.<br>
<br>
<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt">=
<span style=3D"font-size:13px;font-family:Arial;vertical-align:baseline">Th=
e draft is available here:&nbsp;<a href=3D"https://datatracker.ietf.org/doc=
/draft-ietf-opsec-dhcpv6-shield/" target=3D"_blank">https://datatracker.iet=
f.org/doc/draft-ietf-opsec-dhcpv6-shield/</a></span></p>
<br>
<a href=3D"https://datatracker.ietf.org/doc/draft-ietf-opsec-ip-options-fil=
tering/" style=3D"text-decoration:none" target=3D"_blank"><span style=3D"fo=
nt-size:13px;font-family:Arial;text-decoration:underline;vertical-align:bas=
eline"></span></a></div>
<div>Please read it now and report to the list whether you support publicat=
ion or not. Insufficient responses will be taken as an indication of lack o=
f interest and we'll stop from proceeding further.<br>
<br>
</div>
<div>Regards,<br>
</div>
<div>KK (as Opsec WG co-chair)<br>
</div>
</div>
</div>
</div>
</blockquote>
</span>
</body>
</html>

--_000_CF9691291AC75evynckeciscocom_--


From nobody Mon May 12 09:28:01 2014
Return-Path: <robert.sleigh@ee.co.uk>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 994601A0753 for <opsec@ietfa.amsl.com>; Mon, 12 May 2014 09:27:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level: 
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, UNPARSEABLE_RELAY=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DUymhBzaOtJR for <opsec@ietfa.amsl.com>; Mon, 12 May 2014 09:27:55 -0700 (PDT)
Received: from mail1.bemta5.messagelabs.com (mail1.bemta5.messagelabs.com [195.245.231.146]) by ietfa.amsl.com (Postfix) with ESMTP id 108371A0752 for <opsec@ietf.org>; Mon, 12 May 2014 09:27:54 -0700 (PDT)
Received: from [85.158.136.3:56466] by server-10.bemta-5.messagelabs.com id 8B/99-27081-486F0735; Mon, 12 May 2014 16:27:48 +0000
X-Env-Sender: robert.sleigh@ee.co.uk
X-Msg-Ref: server-13.tower-123.messagelabs.com!1399912061!30624153!1
X-Originating-IP: [193.36.79.211]
X-StarScan-Received: 
X-StarScan-Version: 6.11.3; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 11286 invoked from network); 12 May 2014 16:27:41 -0000
Received: from unknown (HELO autechre) (193.36.79.211) by server-13.tower-123.messagelabs.com with SMTP; 12 May 2014 16:27:41 -0000
Received: from UK31S005EXS02.EEAD.EEINT.CO.UK (Not Verified[10.246.208.27]) by autechre with MailMarshal (v6, 8, 2, 9371) id <B5370f6b70000>; Mon, 12 May 2014 17:28:39 +0100
Received: from UK31S005EXS06.EEAD.EEINT.CO.UK ([fe80::d851:f0e3:bba5:c1a0]) by UK31S005EXS02.EEAD.EEINT.CO.UK ([fe80::5093:62a6:6ee3:7198%11]) with mapi id 14.02.0318.004; Mon, 12 May 2014 17:27:40 +0100
From: "Sleigh, Robert" <robert.sleigh@ee.co.uk>
To: "Eric Vyncke (evyncke)" <evyncke@cisco.com>, KK Chittimaneni <kk.chittimaneni@gmail.com>, "opsec@ietf.org" <opsec@ietf.org>
Thread-Topic: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
Thread-Index: AQHPbMbU3Fibc0izRkWpMI7LA/NQHZs83IOAgAAklOA=
Date: Mon, 12 May 2014 16:27:39 +0000
Message-ID: <679694A32AB94046931C676BEF4BA8B80C9257A7@UK31S005EXS06.EEAD.EEINT.CO.UK>
References: <CA+iP7bXkJHgw6W_+q7vgFFf6EgNxWuDB37NSxrLrC6+YScHirg@mail.gmail.com> <CF969129.1AC75%evyncke@cisco.com>
In-Reply-To: <CF969129.1AC75%evyncke@cisco.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.246.208.5]
Content-Type: multipart/alternative; boundary="_000_679694A32AB94046931C676BEF4BA8B80C9257A7UK31S005EXS06EE_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/opsec/EY_3fbLXm33714zKngqGuzKBe-o
Cc: Fernando Gont <fgont@si6networks.com>
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 May 2014 16:27:59 -0000

--_000_679694A32AB94046931C676BEF4BA8B80C9257A7UK31S005EXS06EE_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hi All

This seems like a good step in the right direction, so I think this docum=
ent has some value and should progress but...

Unless this functionality is to be deployed on every switch port across a=
n entire environment (which I grant you, it may well be), I think this wi=
ll only remove the risk entirely if the client and the DHCPv6 server are =
located on the same switch.

It does not necessarily provide full protection for endusers in, for exam=
ple, a routed DHCPv6 relay environment, and I think a similar issue arise=
s in cascading L2 devices.

In a routed DHCPv6 relay environment there will be an ingress port on the=
=20enduser's local switch which will need to be enabled for receiving DHC=
Pv6-server messages, but the switch will be reliant on the upstream devic=
es to have filtered out rogue DHCPv6-server messages, as the local switch=
=20has no way of determining which upstream DHCP-server messages are vali=
d.

Regards

Bob
07958 318592

Life's for sharing... and what I like to share the most is a smile

From: OPSEC [mailto:opsec-bounces@ietf.org] On Behalf Of Eric Vyncke (evy=
ncke)
Sent: 12 May 2014 14:10
To: KK Chittimaneni; opsec@ietf.org
Cc: Fernando Gont
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

KK, Gunter, Fernando & Will,

I have reviewed the document and here are my comments (some cosmetic):

=20 *   section 1: "on a specified port of the layer-2 device" =3D> "on s=
pecific port(s) of the layer-2 device" (plural form)
=20 *   Section 1: "Only those ports to which a DHCPv6 server" =3D> "Only=
=20those ports to which a DHCPv6 server or relay" (relays should be allow=
ed as well)
=20 *   Section 3: not sure whether it is relevant here, this is well-kno=
wn and accepted terminology, I am always uneasy when information is dupli=
cated as it is an open door for inconsistency
=20 *   Section 3: should define what a 'DHCP shield device' is
=20 *   Section 5: I do not agree with point 1) if the specific platform =
cannot handle a long ext header chain, it should be allowed to drop the p=
acket (the MUST NOT should be SHOULD NOT or even a MAY - reversing the pr=
oposed policy). Of course, such platforms cannot claim compatibility with=
=20DHCP-shield
=20 *   Section 5: "SHOULD be logged in an implementation-specific manner=
=20as security fault" =3D> "security alert" or "security event"
=20 *   Section 7: the whole I-D is only handling the physical/wired swit=
ched case while in the introduction it is stated to be 'broadcast network=
'. The security section and/or introduction should mention this.
=20 *   Section 7: should also mention other DHCP related threats? Such a=
s DoS attack against DHCP servers? Amplification/reflection attacks? Of c=
ourse, the mitigation techniques are out of scope, but, I think that the =
threats should be mentioned
=20 *   Add a reference to SAVI-DHCP ?
Else, good document, pretty much like the well-known rogue DHCPv4

-=E9ric

From: Kiran Kumar Chittimaneni <kk.chittimaneni@gmail.com<mailto:kk.chitt=
imaneni@gmail.com>>
Date: dimanche 11 mai 2014 05:12
To: "opsec@ietf.org<mailto:opsec@ietf.org>" <opsec@ietf.org<mailto:opsec@=
ietf.org>>
Subject: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Dear Opsec WG,
The WGLC for this draft technically ended last month with just one respon=
se received. Not enough to move forward.

The co-chairs chatted about this and noted that there was a lot more supp=
ort for this doc during earlier stages. Given that, we'd like to give the=
=20WG a bit more time to review this and extend the LC to the 24th of May=
. Ideally, we'd like to get at least two volunteers who could do a thorou=
gh review of this doc and post their comments to the list.

The draft is available here: https://datatracker.ietf.org/doc/draft-ietf-=
opsec-dhcpv6-shield/

Please read it now and report to the list whether you support publication=
=20or not. Insufficient responses will be taken as an indication of lack =
of interest and we'll stop from proceeding further.
Regards,
KK (as Opsec WG co-chair)

NOTICE AND DISCLAIMER
This e-mail (including any attachments) is intended for the above-named p=
erson(s).  If you are not the intended recipient, notify the sender immed=
iately, delete this email from your system and do not disclose or use for=
=20any purpose. =20
=20
We may monitor all incoming and outgoing emails in line with current legi=
slation. We have taken steps to ensure that this email and attachments ar=
e free from any virus, but it remains your responsibility to ensure that =
viruses do not adversely affect you.=20

EE Limited
Registered in England and Wales
Company Registered Number: 02382161
Registered Office Address: Trident Place, Mosquito Way, Hatfield, Hertfor=
dshire, AL10 9BW

--_000_679694A32AB94046931C676BEF4BA8B80C9257A7UK31S005EXS06EE_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-mi=
crosoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:wo=
rd" xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D=
"http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-885=
9-1">
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">=

<style><!--
/* Font Definitions */
@font-face
=09{font-family:Wingdings;
=09panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
=09{font-family:Wingdings;
=09panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
=09{font-family:Calibri;
=09panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
=09{font-family:Tahoma;
=09panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
=09{margin:0cm;
=09margin-bottom:.0001pt;
=09font-size:12.0pt;
=09font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
=09{mso-style-priority:99;
=09color:blue;
=09text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
=09{mso-style-priority:99;
=09color:purple;
=09text-decoration:underline;}
p
=09{mso-style-priority:99;
=09mso-margin-top-alt:auto;
=09margin-right:0cm;
=09mso-margin-bottom-alt:auto;
=09margin-left:0cm;
=09font-size:12.0pt;
=09font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
=09{mso-style-priority:99;
=09mso-style-link:"Balloon Text Char";
=09margin:0cm;
=09margin-bottom:.0001pt;
=09font-size:8.0pt;
=09font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
=09{mso-style-name:"Balloon Text Char";
=09mso-style-priority:99;
=09mso-style-link:"Balloon Text";
=09font-family:"Tahoma","sans-serif";}
span.EmailStyle20
=09{mso-style-type:personal-reply;
=09font-family:"Calibri","sans-serif";
=09color:#1F497D;}
.MsoChpDefault
=09{mso-style-type:export-only;
=09font-size:10.0pt;}
@page WordSection1
=09{size:612.0pt 792.0pt;
=09margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
=09{page:WordSection1;}
/* List Definitions */
@list l0
=09{mso-list-id:1959026292;
=09mso-list-template-ids:-2092768804;}
@list l0:level1
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:36.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Symbol;}
@list l0:level2
=09{mso-level-number-format:bullet;
=09mso-level-text:o;
=09mso-level-tab-stop:72.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:"Courier New";
=09mso-bidi-font-family:"Times New Roman";}
@list l0:level3
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:108.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Wingdings;}
@list l0:level4
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:144.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Wingdings;}
@list l0:level5
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:180.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Wingdings;}
@list l0:level6
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:216.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Wingdings;}
@list l0:level7
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:252.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Wingdings;}
@list l0:level8
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:288.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Wingdings;}
@list l0:level9
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:324.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Wingdings;}
ol
=09{margin-bottom:0cm;}
ul
=09{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-GB" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Hi All<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">This seems like a goo=
d step in the right direction, so I think this document has some value an=
d should progress but&#8230;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Unless this functiona=
lity is to be deployed on every switch port across an entire environment =
(which I grant you, it may well be), I think this will only remove
=20the risk entirely if the client and the DHCPv6 server are located on t=
he same switch.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">It does not necessari=
ly provide full protection for endusers in, for example, a routed DHCPv6 =
relay environment, and I think a similar issue arises in cascading
=20L2 devices.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">In a routed DHCPv6 re=
lay environment there will be an ingress port on the enduser&#8217;s loca=
l switch which will need to be enabled for receiving DHCPv6-server messag=
es,
=20but the switch will be reliant on the upstream devices to have filtere=
d out rogue DHCPv6-server messages, as the local switch has no way of det=
ermining which upstream DHCP-server messages are valid.
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></sp=
an></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:blue">Regards</span><span style=3D=
"color:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:blue">Bob</span><span style=3D"f=
ont-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;co=
lor:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:blue">07958 318592</span><span s=
tyle=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif=
&quot;;color:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:fuchsia">Life's for sharing... a=
nd what I like to share the most is a smile</span><span style=3D"font-siz=
e:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F=
497D"><o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></sp=
an></p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0c=
m 0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:10.0pt;=
font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><s=
pan lang=3D"EN-US" style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quo=
t;,&quot;sans-serif&quot;"> OPSEC [mailto:opsec-bounces@ietf.org]
<b>On Behalf Of </b>Eric Vyncke (evyncke)<br>
<b>Sent:</b> 12 May 2014 14:10<br>
<b>To:</b> KK Chittimaneni; opsec@ietf.org<br>
<b>Cc:</b> Fernando Gont<br>
<b>Subject:</b> Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield<o:=
p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">KK, Gunter, Fernando &a=
mp; Will,<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span=
></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">I have reviewed the doc=
ument and here are my comments (some cosmetic):<o:p></o:p></span></p>
</div>
<ul type=3D"disc">
<li class=3D"MsoNormal" style=3D"color:black;mso-margin-top-alt:auto;mso-=
margin-bottom-alt:auto;mso-list:l0 level1 lfo1">
<span style=3D"font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;san=
s-serif&quot;">section 1: &quot;on a specified port of the layer-2 device=
&quot; =3D&gt; &quot;on specific port(s) of the layer-2 device&quot; (plu=
ral form)<o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"mso-marg=
in-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo1">
<span style=3D"font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;">Se=
ction 1: &quot;</span>Only those ports to which a DHCPv6 server&quot; =3D=
&gt; &quot;Only those ports to which a DHCPv6 server or relay&quot; (rela=
ys should be allowed as well)<o:p></o:p></li><li class=3D"MsoNormal" styl=
e=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level=
1 lfo1">
<span style=3D"font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;san=
s-serif&quot;;color:black">Section 3: not sure whether it is relevant her=
e, this is well-known and accepted terminology, I am always uneasy when i=
nformation is duplicated as it is an open door for inconsistency</span><o=
:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;ms=
o-margin-bottom-alt:auto;mso-list:l0 level1 lfo1">
Section 3: should define what a 'DHCP shield device' is<o:p></o:p></li><l=
i class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l0 level1 lfo1">
Section 5: I do not agree with point 1) if the specific platform cannot h=
andle a long ext header chain, it should be allowed to drop the packet (t=
he MUST NOT should be SHOULD NOT or even a MAY &#8212; reversing the prop=
osed policy). Of course, such platforms cannot
=20claim compatibility with DHCP-shield<o:p></o:p></li><li class=3D"MsoNo=
rmal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-lis=
t:l0 level1 lfo1">
Section 5: &quot;SHOULD be logged in an implementation-specific manner as=
=20security fault&quot; =3D&gt; &quot;security alert&quot; or &quot;secur=
ity event&quot;<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margi=
n-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo1">
Section 7: the&nbsp;whole&nbsp;I-D is only handling the physical/wired sw=
itched case while in the introduction it is stated to be 'broadcast netwo=
rk'. The security section and/or introduction should mention this.<o:p></=
o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-mar=
gin-bottom-alt:auto;mso-list:l0 level1 lfo1">
Section 7: should also mention other DHCP related threats? Such as DoS at=
tack against DHCP servers? Amplification/reflection attacks? Of course, t=
he mitigation techniques are out of scope, but, I think that the threats =
should be mentioned<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-m=
argin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo1">
Add a reference to SAVI-DHCP ?<o:p></o:p></li></ul>
<div>
<p class=3D"MsoNormal">Else, good document, pretty much like the well-kno=
wn rogue DHCPv4<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">-=E9ric<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span=
></p>
</div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0c=
m 0cm 0cm">
<p class=3D"MsoNormal"><b><span style=3D"font-size:11.0pt;font-family:&qu=
ot;Calibri&quot;,&quot;sans-serif&quot;;color:black">From:
</span></b><span style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot=
;,&quot;sans-serif&quot;;color:black">Kiran Kumar Chittimaneni &lt;<a hre=
f=3D"mailto:kk.chittimaneni@gmail.com">kk.chittimaneni@gmail.com</a>&gt;<=
br>
<b>Date: </b>dimanche 11 mai 2014 05:12<br>
<b>To: </b>&quot;<a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&quo=
t; &lt;<a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&gt;<br>
<b>Subject: </b>[OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield<o:p></=
o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span=
></p>
</div>
<blockquote style=3D"border:none;border-left:solid #B5C4DF 4.5pt;padding:=
0cm 0cm 0cm 4.0pt;margin-left:3.75pt;margin-right:0cm" id=3D"MAC_OUTLOOK_=
ATTRIBUTION_BLOCKQUOTE">
<div>
<div>
<div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font=
-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color=
:black">Dear Opsec WG,<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font=
-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color=
:black">The WGLC for this draft technically ended last month with just on=
e response received. Not enough to move forward.<br>
<br>
The co-chairs chatted about this and noted that there was a lot more supp=
ort for this doc during earlier stages. Given that, we'd like to give the=
=20WG a bit more time to review this and extend the LC to the 24th of May=
. Ideally, we'd like to get at least two
=20volunteers who could do a thorough review of this doc and post their c=
omments to the list.<o:p></o:p></span></p>
<p style=3D"margin:0cm;margin-bottom:.0001pt"><span style=3D"font-size:10=
.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:black">Th=
e draft is available here:&nbsp;<a href=3D"https://datatracker.ietf.org/d=
oc/draft-ietf-opsec-dhcpv6-shield/" target=3D"_blank">https://datatracker=
.ietf.org/doc/draft-ietf-opsec-dhcpv6-shield/</a></span><span style=3D"fo=
nt-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;col=
or:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span=
></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font=
-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color=
:black">Please read it now and report to the list whether you support pub=
lication or not. Insufficient responses will be taken as an indication
=20of lack of interest and we'll stop from proceeding further.<o:p></o:p>=
</span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">Regards,<o:p></o:p></sp=
an></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">KK (as Opsec WG co-chai=
r)<o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</blockquote>
</div>

<P>NOTICE AND DISCLAIMER<BR>This e-mail (including any attachments) is in=
tended=20
for the above-named person(s).&nbsp; If you are not the intended recipien=
t,=20
notify the sender immediately, delete this email from your system and do =
not=20
disclose or use for any purpose.&nbsp; <BR>&nbsp;<BR>We may monitor all i=
ncoming=20
and outgoing emails in line with current legislation. We have taken steps=
=20to=20
ensure that this email and attachments are free from any virus, but it re=
mains=20
your responsibility to ensure that viruses do not adversely affect you. <=
/P>
<P>EE Limited<BR>Registered in England and Wales<BR>Company Registered Nu=
mber:=20
02382161<BR>Registered Office Address: Trident Place, Mosquito Way, Hatfi=
eld,=20
Hertfordshire, AL10 9BW</P>
</body>
</html>

--_000_679694A32AB94046931C676BEF4BA8B80C9257A7UK31S005EXS06EE_--


From nobody Thu May 15 13:19:19 2014
Return-Path: <internet-drafts@ietf.org>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 49E8D1A0158; Thu, 15 May 2014 13:19:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XQM7C2zwfMAM; Thu, 15 May 2014 13:19:14 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 1DB101A0191; Thu, 15 May 2014 13:19:14 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 5.4.2.p3
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20140515201914.1356.80314.idtracker@ietfa.amsl.com>
Date: Thu, 15 May 2014 13:19:14 -0700
Archived-At: http://mailarchive.ietf.org/arch/msg/opsec/YcrN9rD7oe39sOSayGShgUCArFk
Cc: opsec@ietf.org
Subject: [OPSEC] I-D Action: draft-ietf-opsec-lla-only-08.txt
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.15
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 May 2014 20:19:15 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Operational Security Capabilities for IP Network Infrastructure Working Group of the IETF.

        Title           : Using Only Link-Local Addressing Inside an IPv6 Network
        Authors         : Michael Behringer
                          Eric Vyncke
	Filename        : draft-ietf-opsec-lla-only-08.txt
	Pages           : 10
	Date            : 2014-05-15

Abstract:
   In an IPv6 network it is possible to use only link-local addresses on
   infrastructure links between routers.  This document discusses the
   advantages and disadvantages of this approach to help the decision
   process for a given network.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-opsec-lla-only/

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-opsec-lla-only-08

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=draft-ietf-opsec-lla-only-08


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Mon May 26 07:34:53 2014
Return-Path: <carsten.schmoll@fokus.fraunhofer.de>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 70FBA1A016D for <opsec@ietfa.amsl.com>; Mon, 26 May 2014 07:34:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.001
X-Spam-Level: 
X-Spam-Status: No, score=-0.001 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U6zGqnG82l_a for <opsec@ietfa.amsl.com>; Mon, 26 May 2014 07:34:47 -0700 (PDT)
Received: from mx-relay37-dus.antispameurope.com (mx-relay37-dus.antispameurope.com [94.100.134.237]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6C60A1A0160 for <opsec@ietf.org>; Mon, 26 May 2014 07:34:43 -0700 (PDT)
Received: from smtpsrv1.fokus.fraunhofer.de ([195.37.77.166]) by mx-gate37-dus.antispameurope.com; Mon, 26 May 2014 16:34:36 +0200
Received: from CURIE.fokus.fraunhofer.de (curie.fokus.fraunhofer.de [IPv6:2001:638:806:9::203] (may be forged)) by smtpsrv1.fokus.fraunhofer.de (8.14.4/8.14.4) with ESMTP id s4QEYZxl026321 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=OK); Mon, 26 May 2014 16:34:35 +0200
Received: from DIRAC.fokus.fraunhofer.de ([fe80::95a6:a35d:2023:242c]) by CURIE.fokus.fraunhofer.de ([fe80::4405:336c:6211:c99f%16]) with mapi id 14.03.0181.006; Mon, 26 May 2014 16:34:34 +0200
From: "Schmoll, Carsten" <carsten.schmoll@fokus.fraunhofer.de>
To: "Sleigh, Robert" <robert.sleigh@ee.co.uk>, "Eric Vyncke (evyncke)" <evyncke@cisco.com>, KK Chittimaneni <kk.chittimaneni@gmail.com>, "opsec@ietf.org" <opsec@ietf.org>
Thread-Topic: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
Thread-Index: AQHPbMbZqYYYlHbAFkKj3yztxNB1PZs8y8CAgAA3WYCAFgDwEA==
Date: Mon, 26 May 2014 14:34:34 +0000
Message-ID: <45F6EC28CBA2DE418529BD6EBC89A8226BFE6A85@DIRAC.fokus.fraunhofer.de>
References: <CA+iP7bXkJHgw6W_+q7vgFFf6EgNxWuDB37NSxrLrC6+YScHirg@mail.gmail.com> <CF969129.1AC75%evyncke@cisco.com> <679694A32AB94046931C676BEF4BA8B80C9257A7@UK31S005EXS06.EEAD.EEINT.CO.UK>
In-Reply-To: <679694A32AB94046931C676BEF4BA8B80C9257A7@UK31S005EXS06.EEAD.EEINT.CO.UK>
Accept-Language: de-DE, en-US
Content-Language: de-DE
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [2001:638:806:9::121]
x-kse-antivirus-interceptor-info: protection disabled
Content-Type: multipart/alternative; boundary="_000_45F6EC28CBA2DE418529BD6EBC89A8226BFE6A85DIRACfokusfraun_"
MIME-Version: 1.0
X-cloud-security-sender: carsten.schmoll@fokus.fraunhofer.de
X-cloud-security-recipient: opsec@ietf.org
X-cloud-security-Virusscan: CLEAN
X-cloud-security-disclaimer: This E-Mail was scanned by E-Mailservice on mx-gate37-dus with 659572118001
X-cloud-security-connect: smtpsrv1.fokus.fraunhofer.de[195.37.77.166], TLS=, IP=195.37.77.166
X-cloud-security: scantime:.1704
Archived-At: http://mailarchive.ietf.org/arch/msg/opsec/onkn8Bojb7j6QqN-63kggTRRPCs
Cc: Fernando Gont <fgont@si6networks.com>
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 May 2014 14:34:52 -0000

--_000_45F6EC28CBA2DE418529BD6EBC89A8226BFE6A85DIRACfokusfraun_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Dear Fernando, all,

I second this opinion; maybe some additional section could be added to stat=
e the extras issues related to a routed DHCPv6 server environment, and what=
 can (or MUST) be done in such a setup?

As far as wording in this draft goes, I am not sure about the '- ' in "firs=
t-fragment" and in "state-less", but then again I am no English native spea=
ker myself.

Best regards
Carsten

From: OPSEC [mailto:opsec-bounces@ietf.org] On Behalf Of Sleigh, Robert
Sent: Monday, May 12, 2014 6:28 PM
To: Eric Vyncke (evyncke); KK Chittimaneni; opsec@ietf.org
Cc: Fernando Gont
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Hi All

This seems like a good step in the right direction, so I think this documen=
t has some value and should progress but...

Unless this functionality is to be deployed on every switch port across an =
entire environment (which I grant you, it may well be), I think this will o=
nly remove the risk entirely if the client and the DHCPv6 server are locate=
d on the same switch.

It does not necessarily provide full protection for endusers in, for exampl=
e, a routed DHCPv6 relay environment, and I think a similar issue arises in=
 cascading L2 devices.

In a routed DHCPv6 relay environment there will be an ingress port on the e=
nduser's local switch which will need to be enabled for receiving DHCPv6-se=
rver messages, but the switch will be reliant on the upstream devices to ha=
ve filtered out rogue DHCPv6-server messages, as the local switch has no wa=
y of determining which upstream DHCP-server messages are valid.

Regards

Bob
07958 318592

Life's for sharing... and what I like to share the most is a smile

From: OPSEC [mailto:opsec-bounces@ietf.org] On Behalf Of Eric Vyncke (evync=
ke)
Sent: 12 May 2014 14:10
To: KK Chittimaneni; opsec@ietf.org<mailto:opsec@ietf.org>
Cc: Fernando Gont
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

KK, Gunter, Fernando & Will,

I have reviewed the document and here are my comments (some cosmetic):

  *   section 1: "on a specified port of the layer-2 device" =3D> "on speci=
fic port(s) of the layer-2 device" (plural form)
  *   Section 1: "Only those ports to which a DHCPv6 server" =3D> "Only tho=
se ports to which a DHCPv6 server or relay" (relays should be allowed as we=
ll)
  *   Section 3: not sure whether it is relevant here, this is well-known a=
nd accepted terminology, I am always uneasy when information is duplicated =
as it is an open door for inconsistency
  *   Section 3: should define what a 'DHCP shield device' is
  *   Section 5: I do not agree with point 1) if the specific platform cann=
ot handle a long ext header chain, it should be allowed to drop the packet =
(the MUST NOT should be SHOULD NOT or even a MAY - reversing the proposed p=
olicy). Of course, such platforms cannot claim compatibility with DHCP-shie=
ld
  *   Section 5: "SHOULD be logged in an implementation-specific manner as =
security fault" =3D> "security alert" or "security event"
  *   Section 7: the whole I-D is only handling the physical/wired switched=
 case while in the introduction it is stated to be 'broadcast network'. The=
 security section and/or introduction should mention this.
  *   Section 7: should also mention other DHCP related threats? Such as Do=
S attack against DHCP servers? Amplification/reflection attacks? Of course,=
 the mitigation techniques are out of scope, but, I think that the threats =
should be mentioned
  *   Add a reference to SAVI-DHCP ?
Else, good document, pretty much like the well-known rogue DHCPv4

-=E9ric

From: Kiran Kumar Chittimaneni <kk.chittimaneni@gmail.com<mailto:kk.chittim=
aneni@gmail.com>>
Date: dimanche 11 mai 2014 05:12
To: "opsec@ietf.org<mailto:opsec@ietf.org>" <opsec@ietf.org<mailto:opsec@ie=
tf.org>>
Subject: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Dear Opsec WG,
The WGLC for this draft technically ended last month with just one response=
 received. Not enough to move forward.

The co-chairs chatted about this and noted that there was a lot more suppor=
t for this doc during earlier stages. Given that, we'd like to give the WG =
a bit more time to review this and extend the LC to the 24th of May. Ideall=
y, we'd like to get at least two volunteers who could do a thorough review =
of this doc and post their comments to the list.

The draft is available here: https://datatracker.ietf.org/doc/draft-ietf-op=
sec-dhcpv6-shield/

Please read it now and report to the list whether you support publication o=
r not. Insufficient responses will be taken as an indication of lack of int=
erest and we'll stop from proceeding further.
Regards,
KK (as Opsec WG co-chair)

NOTICE AND DISCLAIMER
This e-mail (including any attachments) is intended for the above-named per=
son(s).  If you are not the intended recipient, notify the sender immediate=
ly, delete this email from your system and do not disclose or use for any p=
urpose.

We may monitor all incoming and outgoing emails in line with current legisl=
ation. We have taken steps to ensure that this email and attachments are fr=
ee from any virus, but it remains your responsibility to ensure that viruse=
s do not adversely affect you.

EE Limited
Registered in England and Wales
Company Registered Number: 02382161
Registered Office Address: Trident Place, Mosquito Way, Hatfield, Hertfords=
hire, AL10 9BW

--_000_45F6EC28CBA2DE418529BD6EBC89A8226BFE6A85DIRACfokusfraun_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:"Segoe UI";
	panose-1:2 11 5 2 4 2 4 2 2 3;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Sprechblasentext Zchn";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.SprechblasentextZchn
	{mso-style-name:"Sprechblasentext Zchn";
	mso-style-priority:99;
	mso-style-link:Sprechblasentext;
	font-family:"Segoe UI","sans-serif";}
p.BalloonText, li.BalloonText, div.BalloonText
	{mso-style-name:"Balloon Text";
	mso-style-link:"Balloon Text Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.E-MailFormatvorlage22
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.E-MailFormatvorlage23
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:632828731;
	mso-list-template-ids:611095476;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1
	{mso-list-id:1959026292;
	mso-list-template-ids:-2092768804;}
@list l1:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l1:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"DE" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D;mso-fareast-language:EN-US=
">Dear Fernando, all,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D;mso-fareast-language:EN-US=
"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D;mso-fareast=
-language:EN-US">I second this opinion; maybe some additional section could=
 be added to state the extras issues related to a routed DHCPv6
 server environment, and what can (or MUST) be done in such a setup?<o:p></=
o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D;mso-fareast=
-language:EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D;mso-fareast=
-language:EN-US">As far as wording in this draft goes, I am not sure about =
the &#8216;- &#8216; in &#8220;first-fragment&#8221; and in &#8220;state-le=
ss&#8221;, but then
 again I am no English native speaker myself.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D;mso-fareast=
-language:EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D;mso-fareast=
-language:EN-US">Best regards<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D;mso-fareast=
-language:EN-US">Carsten<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D;mso-fareast=
-language:EN-US"><o:p>&nbsp;</o:p></span></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span style=3D"font-size:11.0pt;font-family:&quot=
;Calibri&quot;,&quot;sans-serif&quot;">From:</span></b><span style=3D"font-=
size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"> OPSEC =
[mailto:opsec-bounces@ietf.org]
<b>On Behalf Of </b>Sleigh, Robert<br>
<b>Sent:</b> Monday, May 12, 2014 6:28 PM<br>
<b>To:</b> Eric Vyncke (evyncke); KK Chittimaneni; opsec@ietf.org<br>
<b>Cc:</b> Fernando Gont<br>
<b>Subject:</b> Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield<o:p>=
</o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Hi All<o:p=
></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp=
;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">This seems=
 like a good step in the right direction, so I think this document has some=
 value and should progress but&#8230;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp=
;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Unless thi=
s functionality is to be deployed on every switch port across an entire env=
ironment (which I grant you, it may well be), I think this
 will only remove the risk entirely if the client and the DHCPv6 server are=
 located on the same switch.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp=
;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">It does no=
t necessarily provide full protection for endusers in, for example, a route=
d DHCPv6 relay environment, and I think a similar issue arises
 in cascading L2 devices.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp=
;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">In a route=
d DHCPv6 relay environment there will be an ingress port on the enduser&#82=
17;s local switch which will need to be enabled for receiving DHCPv6-server
 messages, but the switch will be reliant on the upstream devices to have f=
iltered out rogue DHCPv6-server messages, as the local switch has no way of=
 determining which upstream DHCP-server messages are valid.
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp=
;</o:p></span></p>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:blue">Regards</span><=
span lang=3D"EN-GB" style=3D"color:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;<o:p=
></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:blue">Bob</span><span=
 lang=3D"EN-GB" style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&=
quot;sans-serif&quot;;color:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:blue">07958 318592</s=
pan><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-family:&quot;Calibr=
i&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;<o:p=
></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.0pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:fuchsia">Life's for s=
haring... and what I like to share the most is a smile</span><span lang=3D"=
EN-GB" style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans=
-serif&quot;;color:#1F497D"><o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp=
;</o:p></span></p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:10.0pt;fo=
nt-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span =
lang=3D"EN-US" style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&qu=
ot;sans-serif&quot;"> OPSEC [<a href=3D"mailto:opsec-bounces@ietf.org">mail=
to:opsec-bounces@ietf.org</a>]
<b>On Behalf Of </b>Eric Vyncke (evyncke)<br>
<b>Sent:</b> 12 May 2014 14:10<br>
<b>To:</b> KK Chittimaneni; <a href=3D"mailto:opsec@ietf.org">opsec@ietf.or=
g</a><br>
<b>Cc:</b> Fernando Gont<br>
<b>Subject:</b> Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield<o:p>=
</o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB"><o:p>&nbsp;</o:p></span></p>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.5pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">KK, Gunter, =
Fernando &amp; Will,<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.5pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;<=
/o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.5pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">I have revie=
wed the document and here are my comments (some cosmetic):<o:p></o:p></span=
></p>
</div>
<ul type=3D"disc">
<li class=3D"MsoNormal" style=3D"color:black;mso-margin-top-alt:auto;mso-ma=
rgin-bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB" style=3D"font-size:10.5pt;font-family:&quot;Calibri&qu=
ot;,&quot;sans-serif&quot;">section 1: &quot;on a specified port of the lay=
er-2 device&quot; =3D&gt; &quot;on specific port(s) of the layer-2 device&q=
uot; (plural form)<o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"m=
so-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB" style=3D"font-family:&quot;Calibri&quot;,&quot;sans-se=
rif&quot;">Section 1: &quot;</span><span lang=3D"EN-GB">Only those ports to=
 which a DHCPv6 server&quot; =3D&gt; &quot;Only those ports to which a DHCP=
v6 server or relay&quot; (relays should be allowed as well)<o:p></o:p></spa=
n></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-=
bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB" style=3D"font-size:10.5pt;font-family:&quot;Calibri&qu=
ot;,&quot;sans-serif&quot;;color:black">Section 3: not sure whether it is r=
elevant here, this is well-known and accepted terminology, I am always unea=
sy when information is duplicated as it is an open door
 for inconsistency</span><span lang=3D"EN-GB"><o:p></o:p></span></li><li cl=
ass=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:au=
to;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB">Section 3: should define what a 'DHCP shield device' i=
s<o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt=
:auto;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB">Section 5: I do not agree with point 1) if the specifi=
c platform cannot handle a long ext header chain, it should be allowed to d=
rop the packet (the MUST NOT should be SHOULD NOT or even a MAY &#8212; rev=
ersing the proposed policy). Of course,
 such platforms cannot claim compatibility with DHCP-shield<o:p></o:p></spa=
n></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-=
bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB">Section 5: &quot;SHOULD be logged in an implementation=
-specific manner as security fault&quot; =3D&gt; &quot;security alert&quot;=
 or &quot;security event&quot;<o:p></o:p></span></li><li class=3D"MsoNormal=
" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l1 l=
evel1 lfo3">
<span lang=3D"EN-GB">Section 7: the&nbsp;whole&nbsp;I-D is only handling th=
e physical/wired switched case while in the introduction it is stated to be=
 'broadcast network'. The security section and/or introduction should menti=
on this.<o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"mso-margin-=
top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB">Section 7: should also mention other DHCP related thre=
ats? Such as DoS attack against DHCP servers? Amplification/reflection atta=
cks? Of course, the mitigation techniques are out of scope, but, I think th=
at the threats should be mentioned<o:p></o:p></span></li><li class=3D"MsoNo=
rmal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:=
l1 level1 lfo3">
<span lang=3D"EN-GB">Add a reference to SAVI-DHCP ?<o:p></o:p></span></li><=
/ul>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB">Else, good document, pretty muc=
h like the well-known rogue DHCPv4<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB"><o:p>&nbsp;</o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB">-=E9ric<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.5pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;<=
/o:p></span></p>
</div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-GB" style=3D"font-size:11.0pt;fo=
nt-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">From:
</span></b><span lang=3D"EN-GB" style=3D"font-size:11.0pt;font-family:&quot=
;Calibri&quot;,&quot;sans-serif&quot;;color:black">Kiran Kumar Chittimaneni=
 &lt;<a href=3D"mailto:kk.chittimaneni@gmail.com">kk.chittimaneni@gmail.com=
</a>&gt;<br>
<b>Date: </b>dimanche 11 mai 2014 05:12<br>
<b>To: </b>&quot;<a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&quot;=
 &lt;<a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&gt;<br>
<b>Subject: </b>[OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield<o:p></o:=
p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.5pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;<=
/o:p></span></p>
</div>
<blockquote style=3D"border:none;border-left:solid #B5C4DF 4.5pt;padding:0c=
m 0cm 0cm 4.0pt;margin-left:3.75pt;margin-top:5.0pt;margin-right:0cm;margin=
-bottom:5.0pt" id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE">
<div>
<div>
<div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-GB" =
style=3D"font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&=
quot;;color:black">Dear Opsec WG,<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-GB" =
style=3D"font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&=
quot;;color:black">The WGLC for this draft technically ended last month wit=
h just one response received. Not enough to move forward.<br>
<br>
The co-chairs chatted about this and noted that there was a lot more suppor=
t for this doc during earlier stages. Given that, we'd like to give the WG =
a bit more time to review this and extend the LC to the 24th of May. Ideall=
y, we'd like to get at least two
 volunteers who could do a thorough review of this doc and post their comme=
nts to the list.<o:p></o:p></span></p>
<p style=3D"margin:0cm;margin-bottom:.0001pt"><span lang=3D"EN-GB" style=3D=
"font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;colo=
r:black">The draft is available here:&nbsp;<a href=3D"https://datatracker.i=
etf.org/doc/draft-ietf-opsec-dhcpv6-shield/" target=3D"_blank">https://data=
tracker.ietf.org/doc/draft-ietf-opsec-dhcpv6-shield/</a></span><span lang=
=3D"EN-GB" style=3D"font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;=
sans-serif&quot;;color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.5pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;<=
/o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-GB" =
style=3D"font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&=
quot;;color:black">Please read it now and report to the list whether you su=
pport publication or not. Insufficient responses will be taken
 as an indication of lack of interest and we'll stop from proceeding furthe=
r.<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.5pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">Regards,<o:p=
></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size:10.5pt;font-=
family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">KK (as Opsec=
 WG co-chair)<o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</blockquote>
<p><span lang=3D"EN-GB">NOTICE AND DISCLAIMER<br>
This e-mail (including any attachments) is intended for the above-named per=
son(s).&nbsp; If you are not the intended recipient, notify the sender imme=
diately, delete this email from your system and do not disclose or use for =
any purpose.&nbsp;
<br>
&nbsp;<br>
We may monitor all incoming and outgoing emails in line with current legisl=
ation. We have taken steps to ensure that this email and attachments are fr=
ee from any virus, but it remains your responsibility to ensure that viruse=
s do not adversely affect you.
<o:p></o:p></span></p>
<p><span lang=3D"EN-GB">EE Limited<br>
Registered in England and Wales<br>
Company Registered Number: 02382161<br>
Registered Office Address: Trident Place, Mosquito Way, Hatfield, Hertfords=
hire, AL10 9BW<o:p></o:p></span></p>
</div>
</body>
</html>

--_000_45F6EC28CBA2DE418529BD6EBC89A8226BFE6A85DIRACfokusfraun_--


From nobody Tue May 27 01:14:47 2014
Return-Path: <evyncke@cisco.com>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 08D921A03DA for <opsec@ietfa.amsl.com>; Tue, 27 May 2014 01:14:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.151
X-Spam-Level: 
X-Spam-Status: No, score=-15.151 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FMjLpCSBkb2b for <opsec@ietfa.amsl.com>; Tue, 27 May 2014 01:14:38 -0700 (PDT)
Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 98C7E1A03E2 for <opsec@ietf.org>; Tue, 27 May 2014 01:14:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=32759; q=dns/txt; s=iport; t=1401178474; x=1402388074; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=5WNz9bY9JOh5NesPWltes4N3suvZ8Vrz7KpGEmxen4s=; b=eH2IrGn9EnLef2wAy75+zgrn9ZdTaetR95aWjDe8dUFXaI8HhwToi2sE ZoBJyOZtE/wekXqqfNsVZvJ9CXlHPBzttMnBLDsuZ9nP2V7gh2W9Mqc/1 qFBx9X0fiXLQvDY2OBEE3+TCDSEExEKGHdWN5FKR4jPkMxsD+MWEmm6N4 Y=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhYFACdIhFOtJA2H/2dsb2JhbABZgkJFUljCFAGBDhZ0giUBAQEELUcFEAIBCBEDAQEBIQEGByERFAkIAgQBDQUZiBUDEQ3Nbw2GGhMEjDyBNAoHASwTDAEEBgEChD4El32Bdo01hXKDOGyBAQkXIg
X-IronPort-AV: E=Sophos;i="4.98,917,1392163200";  d="scan'208,217";a="327943965"
Received: from alln-core-2.cisco.com ([173.36.13.135]) by rcdn-iport-1.cisco.com with ESMTP; 27 May 2014 08:14:33 +0000
Received: from xhc-rcd-x13.cisco.com (xhc-rcd-x13.cisco.com [173.37.183.87]) by alln-core-2.cisco.com (8.14.5/8.14.5) with ESMTP id s4R8EXgF008259 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Tue, 27 May 2014 08:14:33 GMT
Received: from xmb-aln-x02.cisco.com ([169.254.5.121]) by xhc-rcd-x13.cisco.com ([173.37.183.87]) with mapi id 14.03.0123.003; Tue, 27 May 2014 03:14:33 -0500
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: "Schmoll, Carsten" <carsten.schmoll@fokus.fraunhofer.de>, "Sleigh, Robert" <robert.sleigh@ee.co.uk>, KK Chittimaneni <kk.chittimaneni@gmail.com>, "opsec@ietf.org" <opsec@ietf.org>
Thread-Topic: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
Thread-Index: AQHPbMbYfZxAQufNXkuwA/o7IiWXMps8y8CAgAA3WYCAFgDwEIABnyGA
Date: Tue, 27 May 2014 08:14:33 +0000
Message-ID: <CFAA1593.1C660%evyncke@cisco.com>
References: <CA+iP7bXkJHgw6W_+q7vgFFf6EgNxWuDB37NSxrLrC6+YScHirg@mail.gmail.com> <CF969129.1AC75%evyncke@cisco.com> <679694A32AB94046931C676BEF4BA8B80C9257A7@UK31S005EXS06.EEAD.EEINT.CO.UK> <45F6EC28CBA2DE418529BD6EBC89A8226BFE6A85@DIRAC.fokus.fraunhofer.de>
In-Reply-To: <45F6EC28CBA2DE418529BD6EBC89A8226BFE6A85@DIRAC.fokus.fraunhofer.de>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.4.1.140326
x-originating-ip: [10.55.185.77]
Content-Type: multipart/alternative; boundary="_000_CFAA15931C660evynckeciscocom_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/opsec/CaZWX-Q-htZcXdTp8S13vH6r9KQ
Cc: Fernando Gont <fgont@si6networks.com>
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 08:14:41 -0000

--_000_CFAA15931C660evynckeciscocom_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Bob and Carsten,

I am not sure why you make a difference between a DHCP server and a DHCP re=
lay in this context. Of course, if this is a DHCP relay, then the relay pat=
h should also be trusted (which is usually the case as it is part of the in=
frastructure). My understanding is that this I-D is basically an extension =
of RA guard RFC.

You are also right about the cascading layer-2 switches, this features shou=
ld indeed be deployed on all layer-2 switches of a layer-2 domain.

-=E9ric

From: <Schmoll>, Carsten <carsten.schmoll@fokus.fraunhofer.de<mailto:carste=
n.schmoll@fokus.fraunhofer.de>>
Date: lundi 26 mai 2014 07:34
To: "Sleigh, Robert" <robert.sleigh@ee.co.uk<mailto:robert.sleigh@ee.co.uk>=
>, Eric Vyncke <evyncke@cisco.com<mailto:evyncke@cisco.com>>, Kiran Kumar C=
hittimaneni <kk.chittimaneni@gmail.com<mailto:kk.chittimaneni@gmail.com>>, =
"opsec@ietf.org<mailto:opsec@ietf.org>" <opsec@ietf.org<mailto:opsec@ietf.o=
rg>>
Cc: Fernando Gont <fgont@si6networks.com<mailto:fgont@si6networks.com>>
Subject: RE: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Dear Fernando, all,

I second this opinion; maybe some additional section could be added to stat=
e the extras issues related to a routed DHCPv6 server environment, and what=
 can (or MUST) be done in such a setup?

As far as wording in this draft goes, I am not sure about the =91- =91 in =
=93first-fragment=94 and in =93state-less=94, but then again I am no Englis=
h native speaker myself.

Best regards
Carsten

From: OPSEC [mailto:opsec-bounces@ietf.org] On Behalf Of Sleigh, Robert
Sent: Monday, May 12, 2014 6:28 PM
To: Eric Vyncke (evyncke); KK Chittimaneni; opsec@ietf.org<mailto:opsec@iet=
f.org>
Cc: Fernando Gont
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Hi All

This seems like a good step in the right direction, so I think this documen=
t has some value and should progress but=85

Unless this functionality is to be deployed on every switch port across an =
entire environment (which I grant you, it may well be), I think this will o=
nly remove the risk entirely if the client and the DHCPv6 server are locate=
d on the same switch.

It does not necessarily provide full protection for endusers in, for exampl=
e, a routed DHCPv6 relay environment, and I think a similar issue arises in=
 cascading L2 devices.

In a routed DHCPv6 relay environment there will be an ingress port on the e=
nduser=92s local switch which will need to be enabled for receiving DHCPv6-=
server messages, but the switch will be reliant on the upstream devices to =
have filtered out rogue DHCPv6-server messages, as the local switch has no =
way of determining which upstream DHCP-server messages are valid.

Regards

Bob
07958 318592

Life's for sharing... and what I like to share the most is a smile

From: OPSEC [mailto:opsec-bounces@ietf.org] On Behalf Of Eric Vyncke (evync=
ke)
Sent: 12 May 2014 14:10
To: KK Chittimaneni; opsec@ietf.org<mailto:opsec@ietf.org>
Cc: Fernando Gont
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

KK, Gunter, Fernando & Will,

I have reviewed the document and here are my comments (some cosmetic):

  *   section 1: "on a specified port of the layer-2 device" =3D> "on speci=
fic port(s) of the layer-2 device" (plural form)
  *   Section 1: "Only those ports to which a DHCPv6 server" =3D> "Only tho=
se ports to which a DHCPv6 server or relay" (relays should be allowed as we=
ll)
  *   Section 3: not sure whether it is relevant here, this is well-known a=
nd accepted terminology, I am always uneasy when information is duplicated =
as it is an open door for inconsistency
  *   Section 3: should define what a 'DHCP shield device' is
  *   Section 5: I do not agree with point 1) if the specific platform cann=
ot handle a long ext header chain, it should be allowed to drop the packet =
(the MUST NOT should be SHOULD NOT or even a MAY =97 reversing the proposed=
 policy). Of course, such platforms cannot claim compatibility with DHCP-sh=
ield
  *   Section 5: "SHOULD be logged in an implementation-specific manner as =
security fault" =3D> "security alert" or "security event"
  *   Section 7: the whole I-D is only handling the physical/wired switched=
 case while in the introduction it is stated to be 'broadcast network'. The=
 security section and/or introduction should mention this.
  *   Section 7: should also mention other DHCP related threats? Such as Do=
S attack against DHCP servers? Amplification/reflection attacks? Of course,=
 the mitigation techniques are out of scope, but, I think that the threats =
should be mentioned
  *   Add a reference to SAVI-DHCP ?
Else, good document, pretty much like the well-known rogue DHCPv4

-=E9ric

From: Kiran Kumar Chittimaneni <kk.chittimaneni@gmail.com<mailto:kk.chittim=
aneni@gmail.com>>
Date: dimanche 11 mai 2014 05:12
To: "opsec@ietf.org<mailto:opsec@ietf.org>" <opsec@ietf.org<mailto:opsec@ie=
tf.org>>
Subject: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Dear Opsec WG,
The WGLC for this draft technically ended last month with just one response=
 received. Not enough to move forward.

The co-chairs chatted about this and noted that there was a lot more suppor=
t for this doc during earlier stages. Given that, we'd like to give the WG =
a bit more time to review this and extend the LC to the 24th of May. Ideall=
y, we'd like to get at least two volunteers who could do a thorough review =
of this doc and post their comments to the list.

The draft is available here: https://datatracker.ietf.org/doc/draft-ietf-op=
sec-dhcpv6-shield/

Please read it now and report to the list whether you support publication o=
r not. Insufficient responses will be taken as an indication of lack of int=
erest and we'll stop from proceeding further.
Regards,
KK (as Opsec WG co-chair)

NOTICE AND DISCLAIMER
This e-mail (including any attachments) is intended for the above-named per=
son(s).  If you are not the intended recipient, notify the sender immediate=
ly, delete this email from your system and do not disclose or use for any p=
urpose.

We may monitor all incoming and outgoing emails in line with current legisl=
ation. We have taken steps to ensure that this email and attachments are fr=
ee from any virus, but it remains your responsibility to ensure that viruse=
s do not adversely affect you.

EE Limited
Registered in England and Wales
Company Registered Number: 02382161
Registered Office Address: Trident Place, Mosquito Way, Hatfield, Hertfords=
hire, AL10 9BW

--_000_CFAA15931C660evynckeciscocom_
Content-Type: text/html; charset="Windows-1252"
Content-ID: <2DE14A32D84A534F837FD3452F02065B@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-lin=
e-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-fami=
ly: Calibri, sans-serif; ">
<div>Bob and Carsten,</div>
<div><br>
</div>
<div>I am not sure why you make a difference between a DHCP server and a DH=
CP relay in this context. Of course, if this is a DHCP relay, then the rela=
y path should also be trusted (which is usually the case as it is part of t=
he infrastructure). My understanding
 is that this I-D is basically an extension of RA guard RFC.</div>
<div><br>
</div>
<div>You are also right about the cascading layer-2 switches, this features=
 should indeed be deployed on all layer-2 switches of a layer-2 domain.</di=
v>
<div><br>
</div>
<div>-=E9ric</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div style=3D"font-family:Calibri; font-size:11pt; text-align:left; color:b=
lack; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM:=
 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;=
 BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style=3D"font-weight:bold">From: </span>&lt;Schmoll&gt;, Carsten &lt;=
<a href=3D"mailto:carsten.schmoll@fokus.fraunhofer.de">carsten.schmoll@foku=
s.fraunhofer.de</a>&gt;<br>
<span style=3D"font-weight:bold">Date: </span>lundi 26 mai 2014 07:34<br>
<span style=3D"font-weight:bold">To: </span>&quot;Sleigh, Robert&quot; &lt;=
<a href=3D"mailto:robert.sleigh@ee.co.uk">robert.sleigh@ee.co.uk</a>&gt;, E=
ric Vyncke &lt;<a href=3D"mailto:evyncke@cisco.com">evyncke@cisco.com</a>&g=
t;, Kiran Kumar Chittimaneni &lt;<a href=3D"mailto:kk.chittimaneni@gmail.co=
m">kk.chittimaneni@gmail.com</a>&gt;,
 &quot;<a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&quot; &lt;<a hr=
ef=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&gt;<br>
<span style=3D"font-weight:bold">Cc: </span>Fernando Gont &lt;<a href=3D"ma=
ilto:fgont@si6networks.com">fgont@si6networks.com</a>&gt;<br>
<span style=3D"font-weight:bold">Subject: </span>RE: [OPSEC] Progressing dr=
aft-ietf-opsec-dhcpv6-shield<br>
</div>
<div><br>
</div>
<blockquote id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style=3D"BORDER-LEFT:=
 #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micro=
soft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" x=
mlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:/=
/www.w3.org/TR/REC-html40">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:"Segoe UI";
	panose-1:2 11 5 2 4 2 4 2 2 3;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Sprechblasentext Zchn";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.SprechblasentextZchn
	{mso-style-name:"Sprechblasentext Zchn";
	mso-style-priority:99;
	mso-style-link:Sprechblasentext;
	font-family:"Segoe UI","sans-serif";}
p.BalloonText, li.BalloonText, div.BalloonText
	{mso-style-name:"Balloon Text";
	mso-style-link:"Balloon Text Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.E-MailFormatvorlage22
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.E-MailFormatvorlage23
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:632828731;
	mso-list-template-ids:611095476;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1
	{mso-list-id:1959026292;
	mso-list-template-ids:-2092768804;}
@list l1:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l1:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l1:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
<div lang=3D"DE" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size: 11pt; font-family: Calibri=
, sans-serif; color: rgb(31, 73, 125); ">Dear Fernando, all,<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size: 11pt; font-family: Calibri=
, sans-serif; color: rgb(31, 73, 125); "><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">I second this opini=
on; maybe some additional section could be added to state the extras issues=
 related to a routed DHCPv6 server environment,
 and what can (or MUST) be done in such a setup?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); "><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">As far as wording i=
n this draft goes, I am not sure about the =91- =91 in =93first-fragment=94=
 and in =93state-less=94, but then again I am no English
 native speaker myself.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); "><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">Best regards<o:p></=
o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">Carsten<o:p></o:p><=
/span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); "><o:p>&nbsp;</o:p></=
span></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span style=3D"font-size: 11pt; font-family: Cali=
bri, sans-serif; ">From:</span></b><span style=3D"font-size: 11pt; font-fam=
ily: Calibri, sans-serif; "> OPSEC [<a href=3D"mailto:opsec-bounces@ietf.or=
g">mailto:opsec-bounces@ietf.org</a>]
<b>On Behalf Of </b>Sleigh, Robert<br>
<b>Sent:</b> Monday, May 12, 2014 6:28 PM<br>
<b>To:</b> Eric Vyncke (evyncke); KK Chittimaneni; <a href=3D"mailto:opsec@=
ietf.org">
opsec@ietf.org</a><br>
<b>Cc:</b> Fernando Gont<br>
<b>Subject:</b> Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield<o:p>=
</o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">Hi All<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); "><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">This seems like a g=
ood step in the right direction, so I think this document has some value an=
d should progress but=85<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); "><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">Unless this functio=
nality is to be deployed on every switch port across an entire environment =
(which I grant you, it may well be), I
 think this will only remove the risk entirely if the client and the DHCPv6=
 server are located on the same switch.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); "><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">It does not necessa=
rily provide full protection for endusers in, for example, a routed DHCPv6 =
relay environment, and I think a similar
 issue arises in cascading L2 devices.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); "><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">In a routed DHCPv6 =
relay environment there will be an ingress port on the enduser=92s local sw=
itch which will need to be enabled for receiving
 DHCPv6-server messages, but the switch will be reliant on the upstream dev=
ices to have filtered out rogue DHCPv6-server messages, as the local switch=
 has no way of determining which upstream DHCP-server messages are valid.
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); "><o:p>&nbsp;</o:p></=
span></p>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10pt; font-=
family: Arial, sans-serif; color: blue; ">Regards</span><span lang=3D"EN-GB=
" style=3D"color:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">&nbsp;<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10pt; font-=
family: Arial, sans-serif; color: blue; ">Bob</span><span lang=3D"EN-GB" st=
yle=3D"font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73=
, 125); "><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10pt; font-=
family: Arial, sans-serif; color: blue; ">07958 318592</span><span lang=3D"=
EN-GB" style=3D"font-size: 11pt; font-family: Calibri, sans-serif; color: r=
gb(31, 73, 125); "><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); ">&nbsp;<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10pt; font-=
family: Arial, sans-serif; color: fuchsia; ">Life's for sharing... and what=
 I like to share the most is a smile</span><span lang=3D"EN-GB" style=3D"fo=
nt-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); "=
><o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-=
family: Calibri, sans-serif; color: rgb(31, 73, 125); "><o:p>&nbsp;</o:p></=
span></p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size: 10pt; fo=
nt-family: Tahoma, sans-serif; ">From:</span></b><span lang=3D"EN-US" style=
=3D"font-size: 10pt; font-family: Tahoma, sans-serif; "> OPSEC [<a href=3D"=
mailto:opsec-bounces@ietf.org">mailto:opsec-bounces@ietf.org</a>]
<b>On Behalf Of </b>Eric Vyncke (evyncke)<br>
<b>Sent:</b> 12 May 2014 14:10<br>
<b>To:</b> KK Chittimaneni; <a href=3D"mailto:opsec@ietf.org">opsec@ietf.or=
g</a><br>
<b>Cc:</b> Fernando Gont<br>
<b>Subject:</b> Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield<o:p>=
</o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB"><o:p>&nbsp;</o:p></span></p>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10.5pt; fon=
t-family: Calibri, sans-serif; color: black; ">KK, Gunter, Fernando &amp; W=
ill,<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10.5pt; fon=
t-family: Calibri, sans-serif; color: black; "><o:p>&nbsp;</o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10.5pt; fon=
t-family: Calibri, sans-serif; color: black; ">I have reviewed the document=
 and here are my comments (some cosmetic):<o:p></o:p></span></p>
</div>
<ul type=3D"disc">
<li class=3D"MsoNormal" style=3D"color:black;mso-margin-top-alt:auto;mso-ma=
rgin-bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB" style=3D"font-size: 10.5pt; font-family: Calibri, sans=
-serif; ">section 1: &quot;on a specified port of the layer-2 device&quot; =
=3D&gt; &quot;on specific port(s) of the layer-2 device&quot; (plural form)=
<o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:=
auto;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB" style=3D"font-family: Calibri, sans-serif; ">Section 1=
: &quot;</span><span lang=3D"EN-GB">Only those ports to which a DHCPv6 serv=
er&quot; =3D&gt; &quot;Only those ports to which a DHCPv6 server or relay&q=
uot; (relays should be allowed as well)<o:p></o:p></span></li><li class=3D"=
MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-=
list:l1 level1 lfo3">
<span lang=3D"EN-GB" style=3D"font-size: 10.5pt; font-family: Calibri, sans=
-serif; color: black; ">Section 3: not sure whether it is relevant here, th=
is is well-known and accepted terminology, I am always uneasy when informat=
ion is duplicated as it is an open door
 for inconsistency</span><span lang=3D"EN-GB"><o:p></o:p></span></li><li cl=
ass=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:au=
to;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB">Section 3: should define what a 'DHCP shield device' i=
s<o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt=
:auto;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB">Section 5: I do not agree with point 1) if the specifi=
c platform cannot handle a long ext header chain, it should be allowed to d=
rop the packet (the MUST NOT should be SHOULD NOT or even a MAY =97 reversi=
ng the proposed policy). Of course,
 such platforms cannot claim compatibility with DHCP-shield<o:p></o:p></spa=
n></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-=
bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB">Section 5: &quot;SHOULD be logged in an implementation=
-specific manner as security fault&quot; =3D&gt; &quot;security alert&quot;=
 or &quot;security event&quot;<o:p></o:p></span></li><li class=3D"MsoNormal=
" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l1 l=
evel1 lfo3">
<span lang=3D"EN-GB">Section 7: the&nbsp;whole&nbsp;I-D is only handling th=
e physical/wired switched case while in the introduction it is stated to be=
 'broadcast network'. The security section and/or introduction should menti=
on this.<o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"mso-margin-=
top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo3">
<span lang=3D"EN-GB">Section 7: should also mention other DHCP related thre=
ats? Such as DoS attack against DHCP servers? Amplification/reflection atta=
cks? Of course, the mitigation techniques are out of scope, but, I think th=
at the threats should be mentioned<o:p></o:p></span></li><li class=3D"MsoNo=
rmal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:=
l1 level1 lfo3">
<span lang=3D"EN-GB">Add a reference to SAVI-DHCP ?<o:p></o:p></span></li><=
/ul>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB">Else, good document, pretty muc=
h like the well-known rogue DHCPv4<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB"><o:p>&nbsp;</o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB">-=E9ric<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10.5pt; fon=
t-family: Calibri, sans-serif; color: black; "><o:p>&nbsp;</o:p></span></p>
</div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-GB" style=3D"font-size: 11pt; fo=
nt-family: Calibri, sans-serif; color: black; ">From:
</span></b><span lang=3D"EN-GB" style=3D"font-size: 11pt; font-family: Cali=
bri, sans-serif; color: black; ">Kiran Kumar Chittimaneni &lt;<a href=3D"ma=
ilto:kk.chittimaneni@gmail.com">kk.chittimaneni@gmail.com</a>&gt;<br>
<b>Date: </b>dimanche 11 mai 2014 05:12<br>
<b>To: </b>&quot;<a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&quot;=
 &lt;<a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&gt;<br>
<b>Subject: </b>[OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield<o:p></o:=
p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10.5pt; fon=
t-family: Calibri, sans-serif; color: black; "><o:p>&nbsp;</o:p></span></p>
</div>
<blockquote style=3D"border:none;border-left:solid #B5C4DF 4.5pt;padding:0c=
m 0cm 0cm 4.0pt;margin-left:3.75pt;margin-top:5.0pt;margin-right:0cm;margin=
-bottom:5.0pt" id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE">
<div>
<div>
<div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-GB" =
style=3D"font-size: 10.5pt; font-family: Calibri, sans-serif; color: black;=
 ">Dear Opsec WG,<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-GB" =
style=3D"font-size: 10.5pt; font-family: Calibri, sans-serif; color: black;=
 ">The WGLC for this draft technically ended last month with just one respo=
nse received. Not enough to move forward.<br>
<br>
The co-chairs chatted about this and noted that there was a lot more suppor=
t for this doc during earlier stages. Given that, we'd like to give the WG =
a bit more time to review this and extend the LC to the 24th of May. Ideall=
y, we'd like to get at least two
 volunteers who could do a thorough review of this doc and post their comme=
nts to the list.<o:p></o:p></span></p>
<p style=3D"margin:0cm;margin-bottom:.0001pt"><span lang=3D"EN-GB" style=3D=
"font-size: 10pt; font-family: Arial, sans-serif; color: black; ">The draft=
 is available here:&nbsp;<a href=3D"https://datatracker.ietf.org/doc/draft-=
ietf-opsec-dhcpv6-shield/" target=3D"_blank">https://datatracker.ietf.org/d=
oc/draft-ietf-opsec-dhcpv6-shield/</a></span><span lang=3D"EN-GB" style=3D"=
font-size: 10.5pt; font-family: Calibri, sans-serif; color: black; "><o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10.5pt; fon=
t-family: Calibri, sans-serif; color: black; "><o:p>&nbsp;</o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-GB" =
style=3D"font-size: 10.5pt; font-family: Calibri, sans-serif; color: black;=
 ">Please read it now and report to the list whether you support publicatio=
n or not. Insufficient responses will be
 taken as an indication of lack of interest and we'll stop from proceeding =
further.<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10.5pt; fon=
t-family: Calibri, sans-serif; color: black; ">Regards,<o:p></o:p></span></=
p>
</div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-GB" style=3D"font-size: 10.5pt; fon=
t-family: Calibri, sans-serif; color: black; ">KK (as Opsec WG co-chair)<o:=
p></o:p></span></p>
</div>
</div>
</div>
</div>
</blockquote>
<p><span lang=3D"EN-GB">NOTICE AND DISCLAIMER<br>
This e-mail (including any attachments) is intended for the above-named per=
son(s).&nbsp; If you are not the intended recipient, notify the sender imme=
diately, delete this email from your system and do not disclose or use for =
any purpose.&nbsp;
<br>
&nbsp;<br>
We may monitor all incoming and outgoing emails in line with current legisl=
ation. We have taken steps to ensure that this email and attachments are fr=
ee from any virus, but it remains your responsibility to ensure that viruse=
s do not adversely affect you.
<o:p></o:p></span></p>
<p><span lang=3D"EN-GB">EE Limited<br>
Registered in England and Wales<br>
Company Registered Number: 02382161<br>
Registered Office Address: Trident Place, Mosquito Way, Hatfield, Hertfords=
hire, AL10 9BW<o:p></o:p></span></p>
</div>
</div>
</div>
</blockquote>
</span>
</body>
</html>

--_000_CFAA15931C660evynckeciscocom_--


From nobody Tue May 27 02:03:03 2014
Return-Path: <robert.sleigh@ee.co.uk>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 75F431A004E for <opsec@ietfa.amsl.com>; Tue, 27 May 2014 02:03:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, UNPARSEABLE_RELAY=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4dZ6j9fspySj for <opsec@ietfa.amsl.com>; Tue, 27 May 2014 02:02:57 -0700 (PDT)
Received: from mail1.bemta5.messagelabs.com (mail1.bemta5.messagelabs.com [195.245.231.153]) by ietfa.amsl.com (Postfix) with ESMTP id 1F1D11A002F for <opsec@ietf.org>; Tue, 27 May 2014 02:02:55 -0700 (PDT)
Received: from [85.158.136.3:20432] by server-17.bemta-5.messagelabs.com id F9/CB-09046-BB454835; Tue, 27 May 2014 09:02:51 +0000
X-Env-Sender: robert.sleigh@ee.co.uk
X-Msg-Ref: server-8.tower-123.messagelabs.com!1401181368!38955695!1
X-Originating-IP: [193.36.79.211]
X-StarScan-Received: 
X-StarScan-Version: 6.11.3; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 25484 invoked from network); 27 May 2014 09:02:49 -0000
Received: from unknown (HELO autechre) (193.36.79.211) by server-8.tower-123.messagelabs.com with SMTP; 27 May 2014 09:02:49 -0000
Received: from UK30S005EXS02.EEAD.EEINT.CO.UK (Not Verified[10.246.208.14]) by autechre with MailMarshal (v6, 8, 2, 9371) id <B538454ed0000>; Tue, 27 May 2014 10:03:41 +0100
Received: from UK31S005EXS06.EEAD.EEINT.CO.UK ([fe80::d851:f0e3:bba5:c1a0]) by UK30S005EXS02.EEAD.EEINT.CO.UK ([2002:62c:2a4f::62c:2a4f]) with mapi id 14.02.0318.004; Tue, 27 May 2014 10:02:48 +0100
From: "Sleigh, Robert" <robert.sleigh@ee.co.uk>
To: "Eric Vyncke (evyncke)" <evyncke@cisco.com>, "Schmoll, Carsten" <carsten.schmoll@fokus.fraunhofer.de>, KK Chittimaneni <kk.chittimaneni@gmail.com>, "opsec@ietf.org" <opsec@ietf.org>
Thread-Topic: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
Thread-Index: AQHPbMbU3Fibc0izRkWpMI7LA/NQHZs83IOAgAAklOCAFfPRAIABKCiAgAAaoOA=
Date: Tue, 27 May 2014 09:02:47 +0000
Message-ID: <679694A32AB94046931C676BEF4BA8B80C93B497@UK31S005EXS06.EEAD.EEINT.CO.UK>
References: <CA+iP7bXkJHgw6W_+q7vgFFf6EgNxWuDB37NSxrLrC6+YScHirg@mail.gmail.com> <CF969129.1AC75%evyncke@cisco.com> <679694A32AB94046931C676BEF4BA8B80C9257A7@UK31S005EXS06.EEAD.EEINT.CO.UK> <45F6EC28CBA2DE418529BD6EBC89A8226BFE6A85@DIRAC.fokus.fraunhofer.de> <CFAA1593.1C660%evyncke@cisco.com>
In-Reply-To: <CFAA1593.1C660%evyncke@cisco.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.246.208.5]
Content-Type: multipart/alternative; boundary="_000_679694A32AB94046931C676BEF4BA8B80C93B497UK31S005EXS06EE_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/opsec/LAiR6nOg9lhSwmjm745YMnvZbpA
Cc: Fernando Gont <fgont@si6networks.com>
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 09:03:01 -0000

--_000_679694A32AB94046931C676BEF4BA8B80C93B497UK31S005EXS06EE_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hi Eric

I chose DHCP relays as the example because they will not be in the L2 dom=
ain of the clients, whereas a DHCP server will be.

You are right it's the same issue, you have to trust any inbound packet o=
n the L2 device interconnect, just perhaps a potentially higher risk due =
to the wider scope for exploitation ie all the non-local devices in the c=
lient L2 scope, the relay L2 scope and any interconnected L2 scopes...

Regards

Bob
07958 318592

Life's for sharing... and what I like to share the most is a smile

From: Eric Vyncke (evyncke) [mailto:evyncke@cisco.com]
Sent: 27 May 2014 09:15
To: Schmoll, Carsten; Sleigh, Robert; KK Chittimaneni; opsec@ietf.org
Cc: Fernando Gont
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Bob and Carsten,

I am not sure why you make a difference between a DHCP server and a DHCP =
relay in this context. Of course, if this is a DHCP relay, then the relay=
=20path should also be trusted (which is usually the case as it is part o=
f the infrastructure). My understanding is that this I-D is basically an =
extension of RA guard RFC.

You are also right about the cascading layer-2 switches, this features sh=
ould indeed be deployed on all layer-2 switches of a layer-2 domain.

-=E9ric

From: <Schmoll>, Carsten <carsten.schmoll@fokus.fraunhofer.de<mailto:cars=
ten.schmoll@fokus.fraunhofer.de>>
Date: lundi 26 mai 2014 07:34
To: "Sleigh, Robert" <robert.sleigh@ee.co.uk<mailto:robert.sleigh@ee.co.u=
k>>, Eric Vyncke <evyncke@cisco.com<mailto:evyncke@cisco.com>>, Kiran Kum=
ar Chittimaneni <kk.chittimaneni@gmail.com<mailto:kk.chittimaneni@gmail.c=
om>>, "opsec@ietf.org<mailto:opsec@ietf.org>" <opsec@ietf.org<mailto:opse=
c@ietf.org>>
Cc: Fernando Gont <fgont@si6networks.com<mailto:fgont@si6networks.com>>
Subject: RE: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Dear Fernando, all,

I second this opinion; maybe some additional section could be added to st=
ate the extras issues related to a routed DHCPv6 server environment, and =
what can (or MUST) be done in such a setup?

As far as wording in this draft goes, I am not sure about the '- ' in "fi=
rst-fragment" and in "state-less", but then again I am no English native =
speaker myself.

Best regards
Carsten

From: OPSEC [mailto:opsec-bounces@ietf.org] On Behalf Of Sleigh, Robert
Sent: Monday, May 12, 2014 6:28 PM
To: Eric Vyncke (evyncke); KK Chittimaneni; opsec@ietf.org<mailto:opsec@i=
etf.org>
Cc: Fernando Gont
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Hi All

This seems like a good step in the right direction, so I think this docum=
ent has some value and should progress but...

Unless this functionality is to be deployed on every switch port across a=
n entire environment (which I grant you, it may well be), I think this wi=
ll only remove the risk entirely if the client and the DHCPv6 server are =
located on the same switch.

It does not necessarily provide full protection for endusers in, for exam=
ple, a routed DHCPv6 relay environment, and I think a similar issue arise=
s in cascading L2 devices.

In a routed DHCPv6 relay environment there will be an ingress port on the=
=20enduser's local switch which will need to be enabled for receiving DHC=
Pv6-server messages, but the switch will be reliant on the upstream devic=
es to have filtered out rogue DHCPv6-server messages, as the local switch=
=20has no way of determining which upstream DHCP-server messages are vali=
d.

Regards

Bob
07958 318592

Life's for sharing... and what I like to share the most is a smile

From: OPSEC [mailto:opsec-bounces@ietf.org] On Behalf Of Eric Vyncke (evy=
ncke)
Sent: 12 May 2014 14:10
To: KK Chittimaneni; opsec@ietf.org<mailto:opsec@ietf.org>
Cc: Fernando Gont
Subject: Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

KK, Gunter, Fernando & Will,

I have reviewed the document and here are my comments (some cosmetic):

=20 *   section 1: "on a specified port of the layer-2 device" =3D> "on s=
pecific port(s) of the layer-2 device" (plural form)
=20 *   Section 1: "Only those ports to which a DHCPv6 server" =3D> "Only=
=20those ports to which a DHCPv6 server or relay" (relays should be allow=
ed as well)
=20 *   Section 3: not sure whether it is relevant here, this is well-kno=
wn and accepted terminology, I am always uneasy when information is dupli=
cated as it is an open door for inconsistency
=20 *   Section 3: should define what a 'DHCP shield device' is
=20 *   Section 5: I do not agree with point 1) if the specific platform =
cannot handle a long ext header chain, it should be allowed to drop the p=
acket (the MUST NOT should be SHOULD NOT or even a MAY - reversing the pr=
oposed policy). Of course, such platforms cannot claim compatibility with=
=20DHCP-shield
=20 *   Section 5: "SHOULD be logged in an implementation-specific manner=
=20as security fault" =3D> "security alert" or "security event"
=20 *   Section 7: the whole I-D is only handling the physical/wired swit=
ched case while in the introduction it is stated to be 'broadcast network=
'. The security section and/or introduction should mention this.
=20 *   Section 7: should also mention other DHCP related threats? Such a=
s DoS attack against DHCP servers? Amplification/reflection attacks? Of c=
ourse, the mitigation techniques are out of scope, but, I think that the =
threats should be mentioned
=20 *   Add a reference to SAVI-DHCP ?
Else, good document, pretty much like the well-known rogue DHCPv4

-=E9ric

From: Kiran Kumar Chittimaneni <kk.chittimaneni@gmail.com<mailto:kk.chitt=
imaneni@gmail.com>>
Date: dimanche 11 mai 2014 05:12
To: "opsec@ietf.org<mailto:opsec@ietf.org>" <opsec@ietf.org<mailto:opsec@=
ietf.org>>
Subject: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield

Dear Opsec WG,
The WGLC for this draft technically ended last month with just one respon=
se received. Not enough to move forward.

The co-chairs chatted about this and noted that there was a lot more supp=
ort for this doc during earlier stages. Given that, we'd like to give the=
=20WG a bit more time to review this and extend the LC to the 24th of May=
. Ideally, we'd like to get at least two volunteers who could do a thorou=
gh review of this doc and post their comments to the list.

The draft is available here: https://datatracker.ietf.org/doc/draft-ietf-=
opsec-dhcpv6-shield/

Please read it now and report to the list whether you support publication=
=20or not. Insufficient responses will be taken as an indication of lack =
of interest and we'll stop from proceeding further.
Regards,
KK (as Opsec WG co-chair)

NOTICE AND DISCLAIMER
This e-mail (including any attachments) is intended for the above-named p=
erson(s).  If you are not the intended recipient, notify the sender immed=
iately, delete this email from your system and do not disclose or use for=
=20any purpose.

We may monitor all incoming and outgoing emails in line with current legi=
slation. We have taken steps to ensure that this email and attachments ar=
e free from any virus, but it remains your responsibility to ensure that =
viruses do not adversely affect you.

EE Limited
Registered in England and Wales
Company Registered Number: 02382161
Registered Office Address: Trident Place, Mosquito Way, Hatfield, Hertfor=
dshire, AL10 9BW

NOTICE AND DISCLAIMER
This e-mail (including any attachments) is intended for the above-named p=
erson(s).  If you are not the intended recipient, notify the sender immed=
iately, delete this email from your system and do not disclose or use for=
=20any purpose. =20
=20
We may monitor all incoming and outgoing emails in line with current legi=
slation. We have taken steps to ensure that this email and attachments ar=
e free from any virus, but it remains your responsibility to ensure that =
viruses do not adversely affect you.=20

EE Limited
Registered in England and Wales
Company Registered Number: 02382161
Registered Office Address: Trident Place, Mosquito Way, Hatfield, Hertfor=
dshire, AL10 9BW

--_000_679694A32AB94046931C676BEF4BA8B80C93B497UK31S005EXS06EE_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-mi=
crosoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:wo=
rd" xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D=
"http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-885=
9-1">
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">=

<style><!--
/* Font Definitions */
@font-face
=09{font-family:Calibri;
=09panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
=09{font-family:Tahoma;
=09panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
=09{font-family:"Segoe UI";
=09panose-1:2 11 5 2 4 2 4 2 2 3;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
=09{margin:0cm;
=09margin-bottom:.0001pt;
=09font-size:12.0pt;
=09font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
=09{mso-style-priority:99;
=09color:blue;
=09text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
=09{mso-style-priority:99;
=09color:purple;
=09text-decoration:underline;}
p
=09{mso-style-priority:99;
=09mso-margin-top-alt:auto;
=09margin-right:0cm;
=09mso-margin-bottom-alt:auto;
=09margin-left:0cm;
=09font-size:12.0pt;
=09font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
=09{mso-style-priority:99;
=09mso-style-link:"Balloon Text Char";
=09margin:0cm;
=09margin-bottom:.0001pt;
=09font-size:12.0pt;
=09font-family:"Times New Roman","serif";}
span.BalloonTextChar
=09{mso-style-name:"Balloon Text Char";
=09mso-style-priority:99;
=09mso-style-link:"Balloon Text";
=09font-family:"Tahoma","sans-serif";}
p.Sprechblasentext, li.Sprechblasentext, div.Sprechblasentext
=09{mso-style-name:Sprechblasentext;
=09mso-style-link:"Sprechblasentext Zchn";
=09margin:0cm;
=09margin-bottom:.0001pt;
=09font-size:12.0pt;
=09font-family:"Times New Roman","serif";}
span.SprechblasentextZchn
=09{mso-style-name:"Sprechblasentext Zchn";
=09mso-style-priority:99;
=09mso-style-link:Sprechblasentext;
=09font-family:"Segoe UI","sans-serif";}
span.EmailStyle22
=09{mso-style-type:personal;
=09font-family:"Calibri","sans-serif";
=09color:#1F497D;}
span.EmailStyle23
=09{mso-style-type:personal;
=09font-family:"Calibri","sans-serif";
=09color:#1F497D;}
span.EmailStyle24
=09{mso-style-type:personal-reply;
=09font-family:"Calibri","sans-serif";
=09color:#1F497D;}
.MsoChpDefault
=09{mso-style-type:export-only;
=09font-size:10.0pt;}
@page WordSection1
=09{size:612.0pt 792.0pt;
=09margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
=09{page:WordSection1;}
/* List Definitions */
@list l0
=09{mso-list-id:459809160;
=09mso-list-template-ids:648710730;}
@list l0:level1
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:36.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Symbol;}
@list l0:level2
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:72.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Symbol;}
@list l0:level3
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:108.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Symbol;}
@list l0:level4
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:144.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Symbol;}
@list l0:level5
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:180.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Symbol;}
@list l0:level6
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:216.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Symbol;}
@list l0:level7
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:252.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Symbol;}
@list l0:level8
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:288.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Symbol;}
@list l0:level9
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:324.0pt;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09mso-ansi-font-size:10.0pt;
=09font-family:Symbol;}
ol
=09{margin-bottom:0cm;}
ul
=09{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-GB" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Hi Eric<o:p></o:p></s=
pan></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">I chose DHCP relays a=
s the example because they will not be in the L2 domain of the clients, w=
hereas a DHCP server will be.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">You are right it&#821=
7;s the same issue, you have to trust any inbound packet on the L2 device=
=20interconnect, just perhaps a potentially higher risk due to the wider
=20scope for exploitation ie all the non-local devices in the client L2 s=
cope, the relay L2 scope and any interconnected L2 scopes&#8230;<o:p></o:=
p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></sp=
an></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:blue">Regards</span><span style=3D=
"color:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:blue">Bob</span><span style=3D"f=
ont-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;co=
lor:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:blue">07958 318592</span><span s=
tyle=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif=
&quot;;color:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:fuchsia">Life's for sharing... a=
nd what I like to share the most is a smile</span><span style=3D"font-siz=
e:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F=
497D"><o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></sp=
an></p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0c=
m 0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:10.0pt;=
font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><s=
pan lang=3D"EN-US" style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quo=
t;,&quot;sans-serif&quot;"> Eric Vyncke (evyncke) [mailto:evyncke@cisco.c=
om]
<br>
<b>Sent:</b> 27 May 2014 09:15<br>
<b>To:</b> Schmoll, Carsten; Sleigh, Robert; KK Chittimaneni; opsec@ietf.=
org<br>
<b>Cc:</b> Fernando Gont<br>
<b>Subject:</b> Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield<o:=
p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">Bob and Carsten,<o:p></=
o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span=
></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">I am not sure why you m=
ake a difference between a DHCP server and a DHCP relay in this context. =
Of course, if this is a DHCP relay, then the relay path should
=20also be trusted (which is usually the case as it is part of the infras=
tructure). My understanding is that this I-D is basically an extension of=
=20RA guard RFC.<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span=
></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">You are also right abou=
t the cascading layer-2 switches, this features should indeed be deployed=
=20on all layer-2 switches of a layer-2 domain.<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span=
></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">-=E9ric<o:p></o:p></spa=
n></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span=
></p>
</div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0c=
m 0cm 0cm">
<p class=3D"MsoNormal"><b><span style=3D"font-size:11.0pt;font-family:&qu=
ot;Calibri&quot;,&quot;sans-serif&quot;;color:black">From:
</span></b><span style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot=
;,&quot;sans-serif&quot;;color:black">&lt;Schmoll&gt;, Carsten &lt;<a hre=
f=3D"mailto:carsten.schmoll@fokus.fraunhofer.de">carsten.schmoll@fokus.fr=
aunhofer.de</a>&gt;<br>
<b>Date: </b>lundi 26 mai 2014 07:34<br>
<b>To: </b>&quot;Sleigh, Robert&quot; &lt;<a href=3D"mailto:robert.sleigh=
@ee.co.uk">robert.sleigh@ee.co.uk</a>&gt;, Eric Vyncke &lt;<a href=3D"mai=
lto:evyncke@cisco.com">evyncke@cisco.com</a>&gt;, Kiran Kumar Chittimanen=
i &lt;<a href=3D"mailto:kk.chittimaneni@gmail.com">kk.chittimaneni@gmail.=
com</a>&gt;,
=20&quot;<a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&quot; &lt;<=
a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&gt;<br>
<b>Cc: </b>Fernando Gont &lt;<a href=3D"mailto:fgont@si6networks.com">fgo=
nt@si6networks.com</a>&gt;<br>
<b>Subject: </b>RE: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield<o:=
p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span=
></p>
</div>
<blockquote style=3D"border:none;border-left:solid #B5C4DF 4.5pt;padding:=
0cm 0cm 0cm 4.0pt;margin-left:3.75pt;margin-right:0cm" id=3D"MAC_OUTLOOK_=
ATTRIBUTION_BLOCKQUOTE">
<div>
<div>
<p class=3D"MsoNormal"><span lang=3D"DE" style=3D"font-size:11.0pt;font-f=
amily:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Dear Fern=
ando, all,</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p></spa=
n></p>
<p class=3D"MsoNormal"><span lang=3D"DE" style=3D"font-size:11.0pt;font-f=
amily:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</s=
pan><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;fon=
t-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">I seco=
nd this opinion; maybe some additional section could be added to state th=
e extras issues related to a routed DHCPv6 server environment, and
=20what can (or MUST) be done in such a setup?</span><span lang=3D"DE" st=
yle=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;fon=
t-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;=
</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;fon=
t-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">As far=
=20as wording in this draft goes, I am not sure about the &#8216;- &#8216=
; in &#8220;first-fragment&#8221; and in &#8220;state-less&#8221;, but th=
en again I am no English native
=20speaker myself.</span><span lang=3D"DE" style=3D"color:black"><o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;fon=
t-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;=
</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;fon=
t-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Best r=
egards</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></=
p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;fon=
t-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Carste=
n</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;fon=
t-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;=
</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0c=
m 0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"DE" style=3D"font-size:11.0pt;fon=
t-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">From:</s=
pan></b><span lang=3D"DE" style=3D"font-size:11.0pt;font-family:&quot;Cal=
ibri&quot;,&quot;sans-serif&quot;;color:black"> OPSEC [<a href=3D"mailto:=
opsec-bounces@ietf.org">mailto:opsec-bounces@ietf.org</a>]
<b>On Behalf Of </b>Sleigh, Robert<br>
<b>Sent:</b> Monday, May 12, 2014 6:28 PM<br>
<b>To:</b> Eric Vyncke (evyncke); KK Chittimaneni; <a href=3D"mailto:opse=
c@ietf.org">
opsec@ietf.org</a><br>
<b>Cc:</b> Fernando Gont<br>
<b>Subject:</b> Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield</s=
pan><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><span lang=3D"DE" style=3D"color:black">&nbsp;<o:p=
></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Hi All</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">This seems like a goo=
d step in the right direction, so I think this document has some value an=
d should progress but&#8230;</span><span lang=3D"DE" style=3D"color:black=
"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Unless this functiona=
lity is to be deployed on every switch port across an entire environment =
(which I grant you, it may well be), I think this will only remove
=20the risk entirely if the client and the DHCPv6 server are located on t=
he same switch.</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">It does not necessari=
ly provide full protection for endusers in, for example, a routed DHCPv6 =
relay environment, and I think a similar issue arises in cascading
=20L2 devices.</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">In a routed DHCPv6 re=
lay environment there will be an ingress port on the enduser&#8217;s loca=
l switch which will need to be enabled for receiving DHCPv6-server messag=
es,
=20but the switch will be reliant on the upstream devices to have filtere=
d out rogue DHCPv6-server messages, as the local switch has no way of det=
ermining which upstream DHCP-server messages are valid.
</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:blue">Regards</span><span lang=3D=
"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:blue">Bob</span><span lang=3D"DE=
" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:blue">07958 318592</span><span l=
ang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:fuchsia">Life's for sharing... a=
nd what I like to share the most is a smile</span><span lang=3D"DE" style=
=3D"color:black"><o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0c=
m 0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:10.0pt;=
font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:black">From:<=
/span></b><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-family:&quo=
t;Tahoma&quot;,&quot;sans-serif&quot;;color:black"> OPSEC [<a href=3D"mai=
lto:opsec-bounces@ietf.org">mailto:opsec-bounces@ietf.org</a>]
<b>On Behalf Of </b>Eric Vyncke (evyncke)<br>
<b>Sent:</b> 12 May 2014 14:10<br>
<b>To:</b> KK Chittimaneni; <a href=3D"mailto:opsec@ietf.org">opsec@ietf.=
org</a><br>
<b>Cc:</b> Fernando Gont<br>
<b>Subject:</b> Re: [OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield</s=
pan><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span><span lan=
g=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">KK, Gunter, Fernando &a=
mp; Will,</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span=
></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">&nbsp;</span><span lang=
=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">I have reviewed the doc=
ument and here are my comments (some cosmetic):</span><span lang=3D"DE" s=
tyle=3D"color:black"><o:p></o:p></span></p>
</div>
<ul type=3D"disc">
<li class=3D"MsoNormal" style=3D"color:black;mso-margin-top-alt:auto;mso-=
margin-bottom-alt:auto;mso-list:l0 level1 lfo1">
<span style=3D"font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;san=
s-serif&quot;">section 1: &quot;on a specified port of the layer-2 device=
&quot; =3D&gt; &quot;on specific port(s) of the layer-2 device&quot; (plu=
ral form)</span><span lang=3D"DE"><o:p></o:p></span></li><li class=3D"Mso=
Normal" style=3D"color:black;mso-margin-top-alt:auto;mso-margin-bottom-al=
t:auto;mso-list:l0 level1 lfo1">
<span style=3D"font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;">Se=
ction 1: &quot;</span>Only those ports to which a DHCPv6 server&quot; =3D=
&gt; &quot;Only those ports to which a DHCPv6 server or relay&quot; (rela=
ys should be allowed as well)<span lang=3D"DE"><o:p></o:p></span></li><li=
=20class=3D"MsoNormal" style=3D"color:black;mso-margin-top-alt:auto;mso-m=
argin-bottom-alt:auto;mso-list:l0 level1 lfo1">
<span style=3D"font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;san=
s-serif&quot;">Section 3: not sure whether it is relevant here, this is w=
ell-known and accepted terminology, I am always uneasy when information i=
s duplicated as it is an open door for inconsistency</span><span lang=3D"=
DE"><o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"color:black;m=
so-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo1=
">
Section 3: should define what a 'DHCP shield device' is<span lang=3D"DE">=
<o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"color:black;mso-m=
argin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo1">
Section 5: I do not agree with point 1) if the specific platform cannot h=
andle a long ext header chain, it should be allowed to drop the packet (t=
he MUST NOT should be SHOULD NOT or even a MAY &#8212; reversing the prop=
osed policy). Of course, such platforms cannot
=20claim compatibility with DHCP-shield<span lang=3D"DE"><o:p></o:p></spa=
n></li><li class=3D"MsoNormal" style=3D"color:black;mso-margin-top-alt:au=
to;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo1">
Section 5: &quot;SHOULD be logged in an implementation-specific manner as=
=20security fault&quot; =3D&gt; &quot;security alert&quot; or &quot;secur=
ity event&quot;<span lang=3D"DE"><o:p></o:p></span></li><li class=3D"MsoN=
ormal" style=3D"color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt=
:auto;mso-list:l0 level1 lfo1">
Section 7: the&nbsp;whole&nbsp;I-D is only handling the physical/wired sw=
itched case while in the introduction it is stated to be 'broadcast netwo=
rk'. The security section and/or introduction should mention this.<span l=
ang=3D"DE"><o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"color:=
black;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 leve=
l1 lfo1">
Section 7: should also mention other DHCP related threats? Such as DoS at=
tack against DHCP servers? Amplification/reflection attacks? Of course, t=
he mitigation techniques are out of scope, but, I think that the threats =
should be mentioned<span lang=3D"DE"><o:p></o:p></span></li><li class=3D"=
MsoNormal" style=3D"color:black;mso-margin-top-alt:auto;mso-margin-bottom=
-alt:auto;mso-list:l0 level1 lfo1">
Add a reference to SAVI-DHCP ?<span lang=3D"DE"><o:p></o:p></span></li></=
ul>
<div>
<p class=3D"MsoNormal"><span style=3D"color:black">Else, good document, p=
retty much like the well-known rogue DHCPv4</span><span lang=3D"DE" style=
=3D"color:black"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span><span lan=
g=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"color:black">-=E9ric</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">&nbsp;</span><span lang=
=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0c=
m 0cm 0cm">
<p class=3D"MsoNormal"><b><span style=3D"font-size:11.0pt;font-family:&qu=
ot;Calibri&quot;,&quot;sans-serif&quot;;color:black">From:
</span></b><span style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot=
;,&quot;sans-serif&quot;;color:black">Kiran Kumar Chittimaneni &lt;<a hre=
f=3D"mailto:kk.chittimaneni@gmail.com">kk.chittimaneni@gmail.com</a>&gt;<=
br>
<b>Date: </b>dimanche 11 mai 2014 05:12<br>
<b>To: </b>&quot;<a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&quo=
t; &lt;<a href=3D"mailto:opsec@ietf.org">opsec@ietf.org</a>&gt;<br>
<b>Subject: </b>[OPSEC] Progressing draft-ietf-opsec-dhcpv6-shield</span>=
<span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">&nbsp;</span><span lang=
=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
<blockquote style=3D"border:none;border-left:solid #B5C4DF 4.5pt;padding:=
0cm 0cm 0cm 4.0pt;margin-left:3.75pt;margin-top:5.0pt;margin-right:0cm;ma=
rgin-bottom:5.0pt" id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE">
<div>
<div>
<div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font=
-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color=
:black">Dear Opsec WG,</span><span lang=3D"DE" style=3D"color:black"><o:p=
></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font=
-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color=
:black">The WGLC for this draft technically ended last month with just on=
e response received. Not enough to move forward.<br>
<br>
The co-chairs chatted about this and noted that there was a lot more supp=
ort for this doc during earlier stages. Given that, we'd like to give the=
=20WG a bit more time to review this and extend the LC to the 24th of May=
. Ideally, we'd like to get at least two
=20volunteers who could do a thorough review of this doc and post their c=
omments to the list.</span><span lang=3D"DE" style=3D"color:black"><o:p><=
/o:p></span></p>
<p style=3D"margin:0cm;margin-bottom:.0001pt"><span style=3D"font-size:10=
.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:black">Th=
e draft is available here:&nbsp;<a href=3D"https://datatracker.ietf.org/d=
oc/draft-ietf-opsec-dhcpv6-shield/" target=3D"_blank">https://datatracker=
.ietf.org/doc/draft-ietf-opsec-dhcpv6-shield/</a></span><span lang=3D"DE"=
=20style=3D"color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">&nbsp;</span><span lang=
=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font=
-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color=
:black">Please read it now and report to the list whether you support pub=
lication or not. Insufficient responses will be taken as an indication
=20of lack of interest and we'll stop from proceeding further.</span><spa=
n lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">Regards,</span><span la=
ng=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;=
Calibri&quot;,&quot;sans-serif&quot;;color:black">KK (as Opsec WG co-chai=
r)</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</blockquote>
<p><span style=3D"color:black">NOTICE AND DISCLAIMER<br>
This e-mail (including any attachments) is intended for the above-named p=
erson(s).&nbsp; If you are not the intended recipient, notify the sender =
immediately, delete this email from your system and do not disclose or us=
e for any purpose.&nbsp;
<br>
&nbsp;<br>
We may monitor all incoming and outgoing emails in line with current legi=
slation. We have taken steps to ensure that this email and attachments ar=
e free from any virus, but it remains your responsibility to ensure that =
viruses do not adversely affect you.
</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p></span></p>
<p><span style=3D"color:black">EE Limited<br>
Registered in England and Wales<br>
Company Registered Number: 02382161<br>
Registered Office Address: Trident Place, Mosquito Way, Hatfield, Hertfor=
dshire, AL10 9BW</span><span lang=3D"DE" style=3D"color:black"><o:p></o:p=
></span></p>
</div>
</div>
</blockquote>
</div>

<P>NOTICE AND DISCLAIMER<BR>This e-mail (including any attachments) is in=
tended=20
for the above-named person(s).&nbsp; If you are not the intended recipien=
t,=20
notify the sender immediately, delete this email from your system and do =
not=20
disclose or use for any purpose.&nbsp; <BR>&nbsp;<BR>We may monitor all i=
ncoming=20
and outgoing emails in line with current legislation. We have taken steps=
=20to=20
ensure that this email and attachments are free from any virus, but it re=
mains=20
your responsibility to ensure that viruses do not adversely affect you. <=
/P>
<P>EE Limited<BR>Registered in England and Wales<BR>Company Registered Nu=
mber:=20
02382161<BR>Registered Office Address: Trident Place, Mosquito Way, Hatfi=
eld,=20
Hertfordshire, AL10 9BW</P>
</body>
</html>

--_000_679694A32AB94046931C676BEF4BA8B80C93B497UK31S005EXS06EE_--

