base.txt | issue90.txt | |||
---|---|---|---|---|
skipping to change at page 38, line 26 | skipping to change at page 38, line 26 | |||
different communications. A dynamic selection can be provided by an | different communications. A dynamic selection can be provided by an | |||
API, such as the one defined in [23]. | API, such as the one defined in [23]. | |||
7.2 Redirect Addresses | 7.2 Redirect Addresses | |||
If the Target Address and Destination Address fields in the ICMP | If the Target Address and Destination Address fields in the ICMP | |||
Redirect message are equal, then this message is used to inform hosts | Redirect message are equal, then this message is used to inform hosts | |||
that a destination is in fact a neighbor. In this case the receiver | that a destination is in fact a neighbor. In this case the receiver | |||
MUST verify that the given address falls within the range defined by | MUST verify that the given address falls within the range defined by | |||
the router's certificate. Redirect messages failing this check MUST | the router's certificate. Redirect messages failing this check MUST | |||
be silently discarded. | be treated as insecure, as described in Section 7.3. | |||
Note that RFC 2461 rules prevent a host from accepting a Redirect | Note that RFC 2461 rules prevent a host from accepting a Redirect | |||
message from a router that is not its default router. This prevents | message from a router that is not its default router. This prevents | |||
an attacker from tricking a node into redirecting traffic when the | an attacker from tricking a node into redirecting traffic when the | |||
attacker is not the default router. | attacker is not the default router. | |||
7.3 Advertised Prefixes | 7.3 Advertised Prefixes | |||
The router's certificate defines the address range(s) that it is | The router's certificate defines the address range(s) that it is | |||
allowed to advertise securely. A router MAY, however, advertise a | allowed to advertise securely. A router MAY, however, advertise a | |||
End of changes. | ||||
This html diff was produced by rfcdiff v1.06, available from http://www.levkowetz.com/ietf/tools/rfcdiff/ |