Re: [Geopriv] Security considerations for draft-winterbottom-geopriv-held-identity-extensions

From: Bernard Aboba ^lt;bernard_aboba@hotmail.com>
Date: Sat Jan 31 2009 - 10:33:57 EST

> Even in an enterprise, you would use the DHCP server to go
> from IP address to mac address, and then use mac address to switch port.

I'm familiar with at least one situation in which this approach was attempted,
but turned out to not be satisfactory.

The DHCP server only holds information on addresses it assigns. Addresses can
also be assigned by other mechanisms (stateless autoconfig, PPP, static). Since
IPv6 connectivity is preferred in a number of current implementations, and IPv6
autoconfig is popular, if the LIS receives a request over IPv6, DHCP (either v4
or v6) may not be of much help in determining location.

The alternative is to pull down the ARP/ND tables from routers to achieve a more
universal IP:MAC address mapping. Doing this on an enterprise network of any
scale is not simple.

On the other hand, if network access were authenticated (as it would be for
WiMAX, IEEE 802.11 and IEEE 802.1X wired), then there already exists a
mapping between User-Name and location (e.g. NAS-Identifier/NAS-IP-Address/NAS-IPv6-Address)
via RADIUS accounting. This is widely deployed already, since almost every
shipping AAA server makes this information accessible in some form.

_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv
Received on Sat, 31 Jan 2009 07:33:57 -0800

This archive was generated by hypermail 2.1.8 : Sat Jan 31 2009 - 10:34:25 EST