
From jeanmichel.combes@gmail.com  Thu Sep  6 01:34:27 2012
Return-Path: <jeanmichel.combes@gmail.com>
X-Original-To: savi@ietfa.amsl.com
Delivered-To: savi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 898F921F854A for <savi@ietfa.amsl.com>; Thu,  6 Sep 2012 01:34:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sVQiD8vhNY3x for <savi@ietfa.amsl.com>; Thu,  6 Sep 2012 01:34:27 -0700 (PDT)
Received: from mail-ob0-f172.google.com (mail-ob0-f172.google.com [209.85.214.172]) by ietfa.amsl.com (Postfix) with ESMTP id 03C0221F853F for <savi@ietf.org>; Thu,  6 Sep 2012 01:34:26 -0700 (PDT)
Received: by obbwc20 with SMTP id wc20so2159729obb.31 for <savi@ietf.org>; Thu, 06 Sep 2012 01:34:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type; bh=6ko8ria1adlgedyZFKqPASqhW28h+zkNze1G6SK7ETE=; b=WOk6Bbim9mJx2/N7qUX+DRqFGV1UPOtfthLO4AX7IRXIoB1/qtsZVCz3icb3dyv91P UUi14cCddV5WHKuIiVsAIVsG4BoPz0+UaRMziNozb3mVg6RIEPVQLWGCkW1FO/DSmEyT hdnSSzOvQs5dON1milKXUGyjJYplAr4iA8fRFFrY1oEjGdFsXacbLPC6XuKabmnujpFX S+JLEBbAcffoCt7f/qr2d5YCz8g+AHIneo9i3VUyc9ZcjAkN28SvhLKcdFOhrLEsWxX4 eOlsHXDw+90wcOzhf5wtF1RoPmtN3kqewDOpvCQdOzoGIQZS4c8fuPeD++xtIYOcvliX B9mA==
MIME-Version: 1.0
Received: by 10.182.116.2 with SMTP id js2mr991090obb.38.1346920466547; Thu, 06 Sep 2012 01:34:26 -0700 (PDT)
Received: by 10.76.127.79 with HTTP; Thu, 6 Sep 2012 01:34:26 -0700 (PDT)
In-Reply-To: <20120906002129.10667.70960.idtracker@ietfa.amsl.com>
References: <20120906002129.10667.70960.idtracker@ietfa.amsl.com>
Date: Thu, 6 Sep 2012 10:34:26 +0200
Message-ID: <CAA7e52pNaHSYN3qkj_aE72Faz3y4H1+0fW1HfeiQe62Kky7=BQ@mail.gmail.com>
From: Jean-Michel Combes <jeanmichel.combes@gmail.com>
To: SAVI Mailing List <savi@ietf.org>
Content-Type: text/plain; charset=ISO-8859-1
Subject: [savi] Fwd: Help the NomCom: Nominations and Feedback
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Sep 2012 08:34:27 -0000

FYI.

Best regards.

JMC.


---------- Forwarded message ----------
From: NomCom Chair <nomcom-chair@ietf.org>
Date: 2012/9/6
Subject: Help the NomCom: Nominations and Feedback
To: Working Group Chairs <wgchairs@ietf.org>


The IETF Nominations Committee (NomCom) is currently seeking
nominations for individuals to serve on the IESG, IAB, and IAOC.
Additionally, this is an announcement that the NomCom is seeking
feedback on individuals who have accepted nominations for IETF
leadership positions.

It is very important to the NomCom process that we get input from a
broad spectrum of the community. Therefore, in case members of your
working group do not read the IETF announcement and discussion lists,
the NomCom would appreciate your help in disseminating the following
information.

The NomCom website contains information about this year's NomCom
including the positions we are seeking to fill, and the qualifications
required for these positions:

https://www.ietf.org/group/nomcom/2012/

The NomCom is accepting nominations until September 24. Nominations
for any position can be made using the following web tool:

https://www.ietf.org/group/nomcom/2012/nominate

Feedback about individuals who the NomCom is considering can be
providing using the following web tool:

https://www.ietf.org/group/nomcom/2012/input

The feedback tool provides a list of individuals who have agreed to be
considered for each position. We will be updating this list in the coming
weeks as more individuals accept nominations.

Feedback provided to the NomCom is kept strictly confidential!

Note that use of the NomCom web tools require an ietf.org (i.e.,
datatracker) account. You can create an ietf.org account by visiting the
following URL:

https://datatracker.ietf.org/accounts/create/

As an alternative to using the web tools,  you can send email to the
NomCom at nomcom12@ietf.org to make a nomination or provide input to
the committee.

Thank you for your help,
- Matt Lepinski
  nomcom-chair@ietf.org

From internet-drafts@ietf.org  Tue Sep 11 06:04:17 2012
Return-Path: <internet-drafts@ietf.org>
X-Original-To: savi@ietfa.amsl.com
Delivered-To: savi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3534721F87FC; Tue, 11 Sep 2012 06:04:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.485
X-Spam-Level: 
X-Spam-Status: No, score=-102.485 tagged_above=-999 required=5 tests=[AWL=0.114, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nF6WZ-Jwc1Ut; Tue, 11 Sep 2012 06:04:16 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C54B21F8773; Tue, 11 Sep 2012 06:04:16 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.34
Message-ID: <20120911130416.7819.41817.idtracker@ietfa.amsl.com>
Date: Tue, 11 Sep 2012 06:04:16 -0700
Cc: savi@ietf.org
Subject: [savi] I-D Action: draft-ietf-savi-dhcp-15.txt
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Sep 2012 13:04:17 -0000

A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.
 This draft is a work item of the Source Address Validation Improvements Wo=
rking Group of the IETF.

	Title           : SAVI Solution for DHCP
	Author(s)       : Jun Bi
                          Jianping Wu
                          Guang Yao
                          Fred Baker
	Filename        : draft-ietf-savi-dhcp-15.txt
	Pages           : 36
	Date            : 2012-09-11

Abstract:
   This document specifies the procedure for creating bindings between a
   DHCPv4/DHCPv6 assigned source IP address and a binding anchor on a
   SAVI (Source Address Validation Improvements) device.  The bindings
   can be used to filter out packets with forged source IP address in
   DHCP scenario.  This mechanism is proposed as a complement to ingress
   filtering to provide finer granularity source IP address validation.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-savi-dhcp

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-savi-dhcp-15

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-savi-dhcp-15


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From internet-drafts@ietf.org  Mon Sep 17 07:11:40 2012
Return-Path: <internet-drafts@ietf.org>
X-Original-To: savi@ietfa.amsl.com
Delivered-To: savi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A589521F86EE; Mon, 17 Sep 2012 07:11:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.562
X-Spam-Level: 
X-Spam-Status: No, score=-102.562 tagged_above=-999 required=5 tests=[AWL=0.038, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mMJ9Gu8XXYu5; Mon, 17 Sep 2012 07:11:31 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C7BCB21F86E0; Mon, 17 Sep 2012 07:11:31 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.34
Message-ID: <20120917141131.12959.92501.idtracker@ietfa.amsl.com>
Date: Mon, 17 Sep 2012 07:11:31 -0700
Cc: savi@ietf.org
Subject: [savi] I-D Action: draft-ietf-savi-send-08.txt
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Sep 2012 14:11:41 -0000

A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.
 This draft is a work item of the Source Address Validation Improvements Wo=
rking Group of the IETF.

	Title           : SEND-based Source-Address Validation Implementation
	Author(s)       : Marcelo Bagnulo
                          Alberto Garcia-Martinez
	Filename        : draft-ietf-savi-send-08.txt
	Pages           : 32
	Date            : 2012-09-17

Abstract:
   This memo describes SEND SAVI, a mechanism to provide source address
   validation using the SEND protocol.  The proposed mechanism is
   intended to complement ingress filtering techniques to provide a
   finer granularity on the control of the source addresses used.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-savi-send

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-savi-send-08

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-savi-send-08


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From gdaley@au.logicalis.com  Mon Sep 17 21:35:34 2012
Return-Path: <gdaley@au.logicalis.com>
X-Original-To: savi@ietfa.amsl.com
Delivered-To: savi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C6B5521E809E; Mon, 17 Sep 2012 21:35:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.605
X-Spam-Level: 
X-Spam-Status: No, score=-1.605 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RELAY_IS_203=0.994]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aMRcZEsWN1IJ; Mon, 17 Sep 2012 21:35:34 -0700 (PDT)
Received: from smtp1.netstarnetworks.com (smtp1.au.logicalis.com [203.8.7.132]) by ietfa.amsl.com (Postfix) with ESMTP id 7192121E80AC; Mon, 17 Sep 2012 21:35:32 -0700 (PDT)
Received-SPF: None identity=mailfrom; client-ip=203.8.7.161; receiver=smtp1.netstarnetworks.com; envelope-from="gdaley@au.logicalis.com"; x-sender="gdaley@au.logicalis.com"; x-conformance=spf_only
Received-SPF: None identity=helo; client-ip=203.8.7.161; receiver=smtp1.netstarnetworks.com; envelope-from="gdaley@au.logicalis.com"; x-sender="postmaster@sdcexchht.au.logicalis.com"; x-conformance=spf_only
Received: from unknown (HELO sdcexchht.au.logicalis.com) ([203.8.7.161]) by smtp1.netstarnetworks.com with ESMTP; 18 Sep 2012 14:32:03 +1000
Received: from SDCEXCHMS.au.logicalis.com ([10.18.196.50]) by sdcexchht.au.logicalis.com ([fe80::68b7:8880:fefb:f742%12]) with mapi id 14.02.0318.001; Tue, 18 Sep 2012 14:35:25 +1000
From: Greg Daley <gdaley@au.logicalis.com>
To: "'internet-drafts@ietf.org'" <internet-drafts@ietf.org>
Thread-Topic: SAVI SEND RADV validation (was RE: [savi] I-D Action: draft-ietf-savi-send-08.txt)
Thread-Index: Ac2VVc3PhaK8PjPoTpeMRIGk760m3A==
Date: Tue, 18 Sep 2012 04:35:25 +0000
Message-ID: <72381AF1F18BAE4F890A0813768D9928EB765B@sdcexchms.au.logicalis.com>
Accept-Language: en-AU, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.18.196.143]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "savi@ietf.org" <savi@ietf.org>, "'alberto@it.uc3m.es'" <alberto@it.uc3m.es>
Subject: [savi] SAVI SEND RADV validation (was RE: I-D Action: draft-ietf-savi-send-08.txt)
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Sep 2012 04:35:35 -0000

Hi Marcelo and Alberto,=20

Thanks for your work on this.

I am wondering how router validity can be ascertained by the SAVI devices w=
hen the only packets transmitted are:


S.3.3.2;
" The only messages the SEND SAVI device is required to generate for
      SEND SAVI operation are NUD_NSOL messages.  This also simplifies
      the state machine."

RFC 3971 relies not only upon the Cryptographically Generated Address (or o=
ther standalone signature) to validate the authorization of a router, but a=
lso Certificate Path Solicitation and Advertisement, which proves that a lo=
cal routing authority has designated the device to be a router.

Reception of a RADV itself is not sufficient to prove the authorization, an=
d SEND nodes have the potential to transmit an RA if misconfigured (or atta=
cking).

Sincerely,

Greg Daley
Solutions Architect
Logicalis Australia Pty Ltd

m: +61 401 772 770
e: gdaley@au.logicalis.com

www.au.logicalis.com

Level 6, 616 St Kilda Road=20
Melbourne VIC 3004 Australia





-----Original Message-----
From: savi-bounces@ietf.org [mailto:savi-bounces@ietf.org] On Behalf Of int=
ernet-drafts@ietf.org
Sent: Tuesday, 18 September 2012 12:12 AM
To: i-d-announce@ietf.org
Cc: savi@ietf.org
Subject: [savi] I-D Action: draft-ietf-savi-send-08.txt


A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.
 This draft is a work item of the Source Address Validation Improvements Wo=
rking Group of the IETF.

	Title           : SEND-based Source-Address Validation Implementation
	Author(s)       : Marcelo Bagnulo
                          Alberto Garcia-Martinez
	Filename        : draft-ietf-savi-send-08.txt
	Pages           : 32
	Date            : 2012-09-17

Abstract:
   This memo describes SEND SAVI, a mechanism to provide source address
   validation using the SEND protocol.  The proposed mechanism is
   intended to complement ingress filtering techniques to provide a
   finer granularity on the control of the source addresses used.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-savi-send

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-savi-send-08

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-savi-send-08


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
savi mailing list
savi@ietf.org
https://www.ietf.org/mailman/listinfo/savi

From alberto@it.uc3m.es  Tue Sep 18 09:24:16 2012
Return-Path: <alberto@it.uc3m.es>
X-Original-To: savi@ietfa.amsl.com
Delivered-To: savi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6AF4A21F8526; Tue, 18 Sep 2012 09:24:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.299
X-Spam-Level: 
X-Spam-Status: No, score=-6.299 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BAT65VYaobX0; Tue, 18 Sep 2012 09:24:15 -0700 (PDT)
Received: from smtp03.uc3m.es (smtp03.uc3m.es [163.117.176.133]) by ietfa.amsl.com (Postfix) with ESMTP id 1F80D21F8518; Tue, 18 Sep 2012 09:24:14 -0700 (PDT)
X-uc3m-safe: yes
Received: from BOMBO (unknown [163.117.139.80]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: alberto@smtp03.uc3m.es) by smtp03.uc3m.es (Postfix) with ESMTPSA id B4E72FAA195; Tue, 18 Sep 2012 18:24:12 +0200 (CEST)
From: =?iso-8859-1?Q?Alberto_Garc=EDa?= <alberto@it.uc3m.es>
To: "'Greg Daley'" <gdaley@au.logicalis.com>, <internet-drafts@ietf.org>
References: <72381AF1F18BAE4F890A0813768D9928EB765B@sdcexchms.au.logicalis.com>
In-Reply-To: <72381AF1F18BAE4F890A0813768D9928EB765B@sdcexchms.au.logicalis.com>
Date: Tue, 18 Sep 2012 18:24:16 +0200
Message-ID: <001001cd95ba$0c879440$2596bcc0$@it.uc3m.es>
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQImDsm7+QIvSKJ9BrYvGsk0x92M8ZbfS1mg
Content-Language: es
X-TM-AS-Product-Ver: IMSS-7.1.0.1224-6.8.0.1017-19192.000
X-TM-AS-Result: No--28.846-7.0-31-1
X-imss-scan-details: No--28.846-7.0-31-1
Cc: savi@ietf.org
Subject: Re: [savi] SAVI SEND RADV validation (was RE: I-D Action: draft-ietf-savi-send-08.txt)
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Sep 2012 16:24:16 -0000

Hi Greg,
First of all, thanks for reading the draft.

|  -----Mensaje original-----
|  De: savi-bounces@ietf.org [mailto:savi-bounces@ietf.org] En nombre de
|  Greg Daley
|  Enviado el: martes, 18 de septiembre de 2012 6:35
|  Para: 'internet-drafts@ietf.org'
|  CC: savi@ietf.org; 'alberto@it.uc3m.es'
|  Asunto: [savi] SAVI SEND RADV validation (was RE: I-D Action: draft-ietf-
|  savi-send-08.txt)
|  
|  Hi Marcelo and Alberto,
|  
|  Thanks for your work on this.
|  
|  I am wondering how router validity can be ascertained by the SAVI devices
|  when the only packets transmitted are:
|  
|  
|  S.3.3.2;
|  " The only messages the SEND SAVI device is required to generate for
|        SEND SAVI operation are NUD_NSOL messages.  This also simplifies
|        the state machine."
|  
|  RFC 3971 relies not only upon the Cryptographically Generated Address (or
|  other standalone signature) to validate the authorization of a router,
but
|  also Certificate Path Solicitation and Advertisement, which proves that a
|  local routing authority has designated the device to be a router.
|  
|  Reception of a RADV itself is not sufficient to prove the authorization,
and
|  SEND nodes have the potential to transmit an RA if misconfigured (or
|  attacking).

I see your point, and I fully agree with it. In other places of the document
it is stated that CPS/CPAs are required to validate RADV messages:
In section '3.2.  SEND SAVI Device Configuration':
"[...]
   o the SEND SAVI device MUST be configured with at least one Trusted
      port to validate the Certification Paths that is used to validate
      router information.
   o  the SEND SAVI device MAY be configured with Certification Paths.
      The alternative is obtaining them by means of issuing
      Certification Path Solicitation messages, as detailed in the SEND
      specification [RFC3971]."

And in section 3.3.2
"  SEND SAVI devices MUST support the processing of validated CPA
   messages, sent in reply to CPS messages, to acquire certificates used
   to validate ND messages.  In order to process a CPA message received
   from a Validating port, an entry for the source address of the
   message MUST exist in the SEND SAVI Data Base.  CPA messages received
   from Trusted ports are always checked and processed."

Finally, we refer to 'validated RADV' all over the text, which of course
implies SEND validation depending on a Trust Anchor/Certification path.
So I think the draft does address the validation of RADV messages correctly.

This being said, I agree that the sentence you point out to can be more
precise. 
Do you think that the issue is fixed if we replace it with the following
text?:
"The only messages the SEND SAVI device is required to generate specifically
per each source IP  address, in order to determine the state of the port for
the considered address, are NUD_NSOL messages.  This also keeps the state
machine simple."

Regards, and thanks for your comment
Alberto

|  
|  Sincerely,
|  
|  Greg Daley
|  Solutions Architect
|  Logicalis Australia Pty Ltd
|  
|  m: +61 401 772 770
|  e: gdaley@au.logicalis.com
|  
|  www.au.logicalis.com
|  
|  Level 6, 616 St Kilda Road
|  Melbourne VIC 3004 Australia
|  
|  
|  
|  
|  
|  -----Original Message-----
|  From: savi-bounces@ietf.org [mailto:savi-bounces@ietf.org] On Behalf Of
|  internet-drafts@ietf.org
|  Sent: Tuesday, 18 September 2012 12:12 AM
|  To: i-d-announce@ietf.org
|  Cc: savi@ietf.org
|  Subject: [savi] I-D Action: draft-ietf-savi-send-08.txt
|  
|  
|  A New Internet-Draft is available from the on-line Internet-Drafts
|  directories.
|   This draft is a work item of the Source Address Validation Improvements
|  Working Group of the IETF.
|  
|  	Title           : SEND-based Source-Address Validation
Implementation
|  	Author(s)       : Marcelo Bagnulo
|                            Alberto Garcia-Martinez
|  	Filename        : draft-ietf-savi-send-08.txt
|  	Pages           : 32
|  	Date            : 2012-09-17
|  
|  Abstract:
|     This memo describes SEND SAVI, a mechanism to provide source address
|     validation using the SEND protocol.  The proposed mechanism is
|     intended to complement ingress filtering techniques to provide a
|     finer granularity on the control of the source addresses used.
|  
|  
|  The IETF datatracker status page for this draft is:
|  https://datatracker.ietf.org/doc/draft-ietf-savi-send
|  
|  There's also a htmlized version available at:
|  http://tools.ietf.org/html/draft-ietf-savi-send-08
|  
|  A diff from the previous version is available at:
|  http://www.ietf.org/rfcdiff?url2=draft-ietf-savi-send-08
|  
|  
|  Internet-Drafts are also available by anonymous FTP at:
|  ftp://ftp.ietf.org/internet-drafts/
|  
|  _______________________________________________
|  savi mailing list
|  savi@ietf.org
|  https://www.ietf.org/mailman/listinfo/savi
|  _______________________________________________
|  savi mailing list
|  savi@ietf.org
|  https://www.ietf.org/mailman/listinfo/savi


From gdaley@au.logicalis.com  Tue Sep 18 19:58:16 2012
Return-Path: <gdaley@au.logicalis.com>
X-Original-To: savi@ietfa.amsl.com
Delivered-To: savi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A78B921E804B; Tue, 18 Sep 2012 19:58:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.455
X-Spam-Level: 
X-Spam-Status: No, score=-1.455 tagged_above=-999 required=5 tests=[AWL=-0.150, BAYES_00=-2.599, MIME_8BIT_HEADER=0.3, RELAY_IS_203=0.994]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2+FXYkD7xizb; Tue, 18 Sep 2012 19:58:15 -0700 (PDT)
Received: from smtp1.netstarnetworks.com (smtp1.au.logicalis.com [203.8.7.132]) by ietfa.amsl.com (Postfix) with ESMTP id BFFC111E808D; Tue, 18 Sep 2012 19:58:14 -0700 (PDT)
Received-SPF: None identity=mailfrom; client-ip=203.8.7.161; receiver=smtp1.netstarnetworks.com; envelope-from="gdaley@au.logicalis.com"; x-sender="gdaley@au.logicalis.com"; x-conformance=spf_only
Received-SPF: None identity=helo; client-ip=203.8.7.161; receiver=smtp1.netstarnetworks.com; envelope-from="gdaley@au.logicalis.com"; x-sender="postmaster@sdcexchht.au.logicalis.com"; x-conformance=spf_only
Received: from unknown (HELO sdcexchht.au.logicalis.com) ([203.8.7.161]) by smtp1.netstarnetworks.com with ESMTP; 19 Sep 2012 12:54:45 +1000
Received: from SDCEXCHMS.au.logicalis.com ([10.18.196.50]) by sdcexchht.au.logicalis.com ([fe80::68b7:8880:fefb:f742%12]) with mapi id 14.02.0318.001; Wed, 19 Sep 2012 12:58:07 +1000
From: Greg Daley <gdaley@au.logicalis.com>
To: =?iso-8859-1?Q?=27Alberto_Garc=EDa=27?= <alberto@it.uc3m.es>, "internet-drafts@ietf.org" <internet-drafts@ietf.org>
Thread-Topic: [savi] SAVI SEND RADV validation (was RE: I-D Action: draft-ietf-savi-send-08.txt)
Thread-Index: AQHNlboLijpyM+j000GmGcNMCzZnBZeQ+RHA
Date: Wed, 19 Sep 2012 02:58:06 +0000
Message-ID: <72381AF1F18BAE4F890A0813768D9928EB95C9@sdcexchms.au.logicalis.com>
References: <72381AF1F18BAE4F890A0813768D9928EB765B@sdcexchms.au.logicalis.com> <001001cd95ba$0c879440$2596bcc0$@it.uc3m.es>
In-Reply-To: <001001cd95ba$0c879440$2596bcc0$@it.uc3m.es>
Accept-Language: en-AU, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.18.196.143]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "savi@ietf.org" <savi@ietf.org>
Subject: Re: [savi] SAVI SEND RADV validation (was RE: I-D Action: draft-ietf-savi-send-08.txt)
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 19 Sep 2012 02:58:16 -0000

Hi Alberto,=20

Thanks for that.   I had missed the section on the trust paths in that pass=
.=20

The clarifying statement is helpful.

Sincerely,

Greg=20

-----Original Message-----
From: Alberto Garc=EDa [mailto:alberto@it.uc3m.es]=20
Sent: Wednesday, 19 September 2012 2:24 AM
To: Greg Daley; internet-drafts@ietf.org
Cc: savi@ietf.org
Subject: RE: [savi] SAVI SEND RADV validation (was RE: I-D Action: draft-ie=
tf-savi-send-08.txt)

Hi Greg,
First of all, thanks for reading the draft.

|  -----Mensaje original-----
|  De: savi-bounces@ietf.org [mailto:savi-bounces@ietf.org] En nombre de =20
| Greg Daley  Enviado el: martes, 18 de septiembre de 2012 6:35
|  Para: 'internet-drafts@ietf.org'
|  CC: savi@ietf.org; 'alberto@it.uc3m.es'
|  Asunto: [savi] SAVI SEND RADV validation (was RE: I-D Action:=20
| draft-ietf-
|  savi-send-08.txt)
| =20
|  Hi Marcelo and Alberto,
| =20
|  Thanks for your work on this.
| =20
|  I am wondering how router validity can be ascertained by the SAVI=20
| devices  when the only packets transmitted are:
| =20
| =20
|  S.3.3.2;
|  " The only messages the SEND SAVI device is required to generate for
|        SEND SAVI operation are NUD_NSOL messages.  This also simplifies
|        the state machine."
| =20
|  RFC 3971 relies not only upon the Cryptographically Generated Address=20
| (or  other standalone signature) to validate the authorization of a=20
| router,
but
|  also Certificate Path Solicitation and Advertisement, which proves=20
| that a  local routing authority has designated the device to be a router.
| =20
|  Reception of a RADV itself is not sufficient to prove the=20
| authorization,
and
|  SEND nodes have the potential to transmit an RA if misconfigured (or =20
| attacking).

I see your point, and I fully agree with it. In other places of the documen=
t it is stated that CPS/CPAs are required to validate RADV messages:
In section '3.2.  SEND SAVI Device Configuration':
"[...]
   o the SEND SAVI device MUST be configured with at least one Trusted
      port to validate the Certification Paths that is used to validate
      router information.
   o  the SEND SAVI device MAY be configured with Certification Paths.
      The alternative is obtaining them by means of issuing
      Certification Path Solicitation messages, as detailed in the SEND
      specification [RFC3971]."

And in section 3.3.2
"  SEND SAVI devices MUST support the processing of validated CPA
   messages, sent in reply to CPS messages, to acquire certificates used
   to validate ND messages.  In order to process a CPA message received
   from a Validating port, an entry for the source address of the
   message MUST exist in the SEND SAVI Data Base.  CPA messages received
   from Trusted ports are always checked and processed."

Finally, we refer to 'validated RADV' all over the text, which of course im=
plies SEND validation depending on a Trust Anchor/Certification path.
So I think the draft does address the validation of RADV messages correctly=
.

This being said, I agree that the sentence you point out to can be more pre=
cise.=20
Do you think that the issue is fixed if we replace it with the following
text?:
"The only messages the SEND SAVI device is required to generate specificall=
y per each source IP  address, in order to determine the state of the port =
for the considered address, are NUD_NSOL messages.  This also keeps the sta=
te machine simple."

Regards, and thanks for your comment
Alberto

| =20
|  Sincerely,
| =20
|  Greg Daley
|  Solutions Architect
|  Logicalis Australia Pty Ltd
| =20
|  m: +61 401 772 770
|  e: gdaley@au.logicalis.com
| =20
|  www.au.logicalis.com
| =20
|  Level 6, 616 St Kilda Road
|  Melbourne VIC 3004 Australia
| =20
| =20
| =20
| =20
| =20
|  -----Original Message-----
|  From: savi-bounces@ietf.org [mailto:savi-bounces@ietf.org] On Behalf=20
| Of  internet-drafts@ietf.org
|  Sent: Tuesday, 18 September 2012 12:12 AM
|  To: i-d-announce@ietf.org
|  Cc: savi@ietf.org
|  Subject: [savi] I-D Action: draft-ietf-savi-send-08.txt
| =20
| =20
|  A New Internet-Draft is available from the on-line Internet-Drafts =20
| directories.
|   This draft is a work item of the Source Address Validation=20
| Improvements  Working Group of the IETF.
| =20
|  	Title           : SEND-based Source-Address Validation
Implementation
|  	Author(s)       : Marcelo Bagnulo
|                            Alberto Garcia-Martinez
|  	Filename        : draft-ietf-savi-send-08.txt
|  	Pages           : 32
|  	Date            : 2012-09-17
| =20
|  Abstract:
|     This memo describes SEND SAVI, a mechanism to provide source address
|     validation using the SEND protocol.  The proposed mechanism is
|     intended to complement ingress filtering techniques to provide a
|     finer granularity on the control of the source addresses used.
| =20
| =20
|  The IETF datatracker status page for this draft is:
|  https://datatracker.ietf.org/doc/draft-ietf-savi-send
| =20
|  There's also a htmlized version available at:
|  http://tools.ietf.org/html/draft-ietf-savi-send-08
| =20
|  A diff from the previous version is available at:
|  http://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-savi-send-08
| =20
| =20
|  Internet-Drafts are also available by anonymous FTP at:
|  ftp://ftp.ietf.org/internet-drafts/
| =20
|  _______________________________________________
|  savi mailing list
|  savi@ietf.org
|  https://www.ietf.org/mailman/listinfo/savi
|  _______________________________________________
|  savi mailing list
|  savi@ietf.org
|  https://www.ietf.org/mailman/listinfo/savi

