RE: [Pana] Re: review pana spec
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Pana] Re: review pana spec



> "
> 11.8.  IP Address Spoofing
> 
>    Without use of SEND (SEcure Neighbor Discovery [RFC 3971], there is
>    no way to prove the ownership of the IP address presented by
>    the PaC.  Hence an attacker can launch a redirect attack by
>    spoofing a victim's IP address.  It is RECOMMENDED to use SEND to
>    avoid such an attack.
> "

I think it is best if we simply acknowledge the problem and state that the
solution is outside the scope of PANA. Trying to solve that, or make
recommendations, is not our business.

I'd recommend:

   PANA does not provide any means to prove ownership of the IP address 
   presented by the PaC. Hence, an authorized PaC can launch a redirect 
   attack by spoofing a victim's IP address. This problem and its 
   solution are outside the scope of PANA.

Alper


> 
> Regards,
> Yoshihiro Ohba
> 
> 
> >
> >
> >
> > -mohan
> >
> >
> >
> >
> >
> >
> >
> >
> > > -----Original Message-----
> > > From: Yoshihiro Ohba [mailto:yohba at tari.toshiba.com]
> > > Sent: Sunday, November 19, 2006 10:39 AM
> > > To: pana at ietf.org
> > > Subject: [Pana] Preliminary pana-pana draft (13a)
> > >
> > > is available at:
> > >
> > > http://www.panasec.org/docs/editing/pana-spec.html
> > >
> > > (Now we get 17 pages reduction.)
> > >
> > > Please do sanity check to make sure that all resolutions discussed in
> > > IETF67 and over mailing list are reflected appropriately.  Diff from
> > > revision 12 is also available.
> > >
> > > As soon as sanity check is done, I will submit a new revision (13)
> > > which is to be used for IETF last call.
> > >
> > > Regards,
> > > Yoshihiro Ohba
> > >
> > > _______________________________________________
> > > Pana mailing list
> > > Pana at ietf.org
> > > https://www1.ietf.org/mailman/listinfo/pana
> >
> >
> >
> >
> >
> > _______________________________________________
> > Pana mailing list
> > Pana at ietf.org
> > https://www1.ietf.org/mailman/listinfo/pana
> >
> >
> 
> _______________________________________________
> Pana mailing list
> Pana at ietf.org
> https://www1.ietf.org/mailman/listinfo/pana


_______________________________________________
Pana mailing list
Pana at ietf.org
https://www1.ietf.org/mailman/listinfo/pana




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.