[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [secdir]Comments on draft-ietf-shim6-hba-01



On Wed, 26 Apr 2006, Geoff Huston wrote:
We'd like to ask the working group at this stage if there are any further thoughts about the hash based address draft in the light of a security directorate review of the draft. The message thread of that review is attached to this note. (The review was conducted in November and December last year)
I must wonder what has happened in the intervening 5 (or so) months..

But aside from that, EKR wrote:
"A single digital signature that's checked every time you re-home seems quite eminently practical."
I may be a bit dense right now, but I'd like to see at least a sketch 
how that would work.  In particular, Im not sure how that is bound to 
the address so that on-path moving off-path wouldn't cause a 
time-shifting attack.
That said, the HBA's "all addresses must change if one changes" is 
rather onerous, so it could be beneficial if we could make do with 
just CGA.
Note: CGA when used with shim6 doesn't have RF IPR license.

--
Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings