i have another input to IPv6 addressing architecture, which is
        very securty-sensitive.  please review and integrate it before
        publishing the next one.
        draft-itojun-v6ops-v4mapped-harmful-00.txt

itojun


---
4.  Suggested protocol change

o In IPv4 address architecture document [Hinden, 1998] explicitly state
  that IPv4 mapped address is for use within basic API [Gilligan, 1999]
  , and basic API only.  Forbid any other uses.

o Move any document that suggests the use of IPv4 mapped address on wire
  to historic, due to security reasons.

The above change will remove the threat due to the use of IPv4 mapped
address on wire.

Another way is to deprecate RFC2553 section 3.7, however, due to the
wide deployment of applications that use IPv6 basic API, the option is
not feasible.
--------------------------------------------------------------------
IETF IPng Working Group Mailing List
IPng Home Page:                      http://playground.sun.com/ipng
FTP archive:                      ftp://playground.sun.com/pub/ipng
Direct all administrative requests to [EMAIL PROTECTED]
--------------------------------------------------------------------

Reply via email to