[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Captive-portals] IETF 103 call for agenda items



I can't make it to the meeting, but I have some random comments about RFC 7710 - from discussions I've had with people.

1) The API shouldn't be where the UE learns about the captive portal URL (it isn't a solution to the problem of "how does every UE get their unique URL to the portal?" as you still need to get UEs uniquely identified by the API as well).

2) We can't assume all network infrastructures have the option of making a unique URL in each DHCP responses.

3) Because of the above, we can't assume the URL will be using HTTPS from the start. (Because, using http for the RFC 7710 URL would allow for the network to redirect thereby uniquely formatting the URL per UE like it does today).

Re-reading the security considerations - in light of the fact that this WG has largely rejected ICMP for 'notification' because of perceived security concerns, and how the API is still bootstrapped by RFC 7710 (which uses ICMPv6 for 'configuration') - the following statement stands out: because this document removes the need for interception, the attacker may have an easier time performing the attack. :)




On Mon, Oct 29, 2018 at 5:06 PM Tommy Pauly <[email protected]> wrote:
That sounds good to me. We haven't revved the API docs, etc, but using the time to just review next steps and get some more work done on 7710bis would be good.

Best,
Tommy

> On Oct 29, 2018, at 4:49 PM, Erik Kline <[email protected]> wrote:
>
> I propose that this time we'll just meet informally.
>
> There are some administrative things we might bring up, but otherwise
> leave it open for discussion.
>
> -Erik
> On Mon, 22 Oct 2018 at 14:53, Erik Kline <[email protected]> wrote:
>>
>> All,
>>
>> We currently have a 1 hour slot scheduled on Thursday afternoon.  Does
>> anyone who'll be present have any proposed agenda items?
>>
>> The list has been rather quiet of late.  I know I still need to
>> produce a more complete 7710bis, but that hardly warrants a full hour
>> of discussion.
>>
>> If there isn't much to talk about this time, we can give everyone
>> their time back (and perhaps, for some folks, de-conflict this time
>> slot), and reconvene in Prague.
>>
>> Thoughts?
>> -Erik
>
> _______________________________________________
> Captive-portals mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/captive-portals

_______________________________________________
Captive-portals mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/captive-portals