Securing Neighbor Discovery Proxy: Problem Statement
RFC 5909, “Securing Neighbor Discovery Proxy: Problem Statement”, is an Informational document published in July 2010 by J-M. Combes, S. Krishnan, G. Daley. The canonical text is published by the RFC Editor.
Abstract
Neighbor Discovery Proxies are used to provide an address presence on a link for nodes that are no longer present on the link. They allow a node to receive packets directed at its address by allowing another device to perform Neighbor Discovery operations on its behalf.
Neighbor Discovery Proxy is used in Mobile IPv6 and related protocols to provide reachability from nodes on the home network when a Mobile Node is not at home, by allowing the Home Agent to act as proxy. It is also used as a mechanism to allow a global prefix to span multiple links, where proxies act as relays for Neighbor Discovery messages.
Neighbor Discovery Proxy currently cannot be secured using Secure Neighbor Discovery (SEND). Today, SEND assumes that a node advertising an address is the address owner and in possession of appropriate public and private keys for that node. This document describes how existing practice for proxy Neighbor Discovery relates to SEND. This document is not an Internet Standards Track specification; it is published for informational purposes.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 5909 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5908 Network Time Protocol Server Option for DHCPv6
- RFC 5910 Domain Name System Security Extensions Mapping for the Extensible Provisioning Protocol
- RFC 5907 Definitions of Managed Objects for Network Time Protocol Version 4
- RFC 5911 New ASN.1 Modules for Cryptographic Message Syntax and S/MIME
- RFC 5906 Network Time Protocol Version 4: Autokey Specification
- RFC 5912 New ASN.1 Modules for the Public Key Infrastructure Using X.509
- RFC 5905 Network Time Protocol Version 4: Protocol and Algorithms Specification
- RFC 5913 Clearance Attribute and Authority Clearance Constraints Certificate Extension