[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Status of Operational issues with Tiny Fragments in IPv6



On Fri, 26 May 2006, Vishwas Manral wrote:
I did notice the issue being raised in the security overview section.

Firstly it is not just a security issue but issue for all middle
boxes. Also I think security overview probably is not the best place
to specify the solution to the problem. The point I bring forward is
that we need not just a problem statement but also a solution of how
to deal with it.
FWIW, I agree that we can describe the problem (which is mostly 
security-related) in the overview, and already do, to some extent.
This is our charter items 2 and 3.  This WG isn't chartered to specify 
(in the normative sense, e.g., altering RFC 2460) the solution, it 
should likely be done by IPv6 WG or an int-area work item.  I'd fully 
support a clean-up of the IPv6 specification (including more than just 
this issue), but I think folks need to talk to the Internet ADs on 
whether they feel this is the right thing to do and which way to go 
about doing it.
--
Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings