[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[savi] Adopting draft-bagnulo-savi-fcfs/send



Folks -

We had a discussion regarding the adoption of individual Internet drafts
as official documents of the SAVI working group.  I would like to
conclude this discussion for the following two Internet drafts:

- draft-bagnulo-savi-fcfs
- draft-bagnulo-savi-send

The feedback we got at the SAVI meeting in Minneapolis and on this
mailing list shows that there is strong support for the FCFS principle,
which is the baseline of both of the above Internet drafts.  A couple of
issues have been identified, and these will have to be addressed.  But
the issues are no showstoppers in my opinion.  In fact, many of them
apply to specific instantiations of the FCFS principle rather than to
the FCFS principle itself.

I have therefore decided to adopt the above Internet drafts as SAVI
working group documents.  Draft-bagnulo-savi-fcfs will be continued
as draft-ietf-savi-fcfs with Erik Nordmark, Marcelo Bagnulo, and Fred
Baker as editors.  Draft-bagnulo-savi-send will be continued
as draft-ietf-savi-send with Ana Kukec, Marcelo Bagnulo, Jianping Wu,
and Jun Bi as editors.

Of course, the documents are far from completion; there is much work
ahead.  And part of this work will be to address the issues that were
raised during the foregoing discussion.  Those are in summary:

- Lack of support for pre-configured, static addresses (Frank Xia).

- Possible DoS attacks where an attacker tricks a SAVI device into
  blocking an address that a victim host is about to configure (Guang
  Yao).

- Possible loss of synchronizing between a host and the responsible SAVI
  device regarding the host's right to use an address (Guang Yao).

- Need to protect target addresses in Neighbor Discovery messages
  similarly to source addresses in regular packets (Guang Yao).

- Filtering load for switches (Lin Tao):  How much load do we impose on
  a switch by requiring it to filter out and monitoring certain
  packets.

- Strength of binding anchors (Dong Zhang):  SAVI will work with various
  binding anchors of different security strength.  SAVI specifications
  should provide guidance for selecting a binding anchor.  We already
  decided to provide such guidance in SAVI specifications.

As a starting point, I would like the current, unmodified versions of
above Internet drafts to be re-submitted with their new names
(draft-ietf-savi-*).  Editors, please go ahead and do so.

- Christian




Note Well: Messages sent to this mailing list are the opinions of the senders and do not imply endorsement by the IETF.