S_RFC3315_21.5.2_InfoReply.seq - Information-Request/Reply with Reconfigure Authentication Protocol
Server
S_RFC3315_21.5.2_InfoReply.seq [-tooloption ...]
-pkt S_RFC3315_21.5.2_InfoReply.def -tooloption: v6eval tool option
See Also DHCPv6.def
TN(Client1)
|
Link0 -------+-----------+--------------- 3ffe:501:ffff:100::/64
|
NUT(Server1)
The server selects a Reconfigure Key for a client during the
Request/Reply, Solicit/Reply or Information-request/Reply message
exchange. The server records the Reconfigure Key and transmits that
key to the client in an Authentication option in the Reply message.
To provide authentication for a Reconfigure message, the server
selects a replay detection value according to the RDM selected by the
server, and computes an HMAC-MD5 of the Reconfigure message using the
Reconfigure Key for the client.
The server computes the HMAC-MD5 over the entire DHCP Reconfigure message,
including the Authentication option; the HMAC-MD5 field in the Authentication
option is set to zero for the HMAC-MD5 computation. The server
includes the HMAC-MD5 in the authentication information field in an
Authentication option included in the Reconfigure message sent to the
client.
Enable Reconfigure Authenticaion Protocol Service
| Device Name |
Device Type |
I/F |
Assigned Prefix |
Link Local Addr |
MAC Addr |
Op1 |
Op2 |
| Server1 |
NUT |
Link0 |
3ffe:501:ffff:100::/64 |
NUT's Linklocal address |
NUT's MAC address |
N/A |
N/A |
| Client1 |
TN |
Link0 |
3ffe:501:ffff:100::/64 |
fe80::200:ff:fe00:a2a2 |
00:00:00:00:a2:a2 |
N/A |
Yes |
Op1: Server ID Option
Op2: Client ID Option
NUT TN
| |
| | Initialize NUT (as a DHCPv6 Server)
| |
| <---- | Information Request with Authentication Accept Option
| | and Option Request Option(Preference Option)
| ----> | Reply with Authentication Option and Preference Option(10)(*1)
| |
| | Preference changed from 10 to 20
| | Reload server configuration
| |
| ----> | Reconfigure with comptuted Authentication (w/Authentication Option) (*2)
| | w/Reconfigure Message Option(msg-type=11)
| |
| <---- | Information-Request with Option Request Option(Preference Option)
| ----> | Reply Preference Option(20)(*3)
| |
(*1) PASS: TN receive Reply message with Authenticaion option including key-ID.
(*2) PASS: TN receive Reconfigure message with Authentication option including msg-type = 11.
(*3) PASS: TN receive Reply message with updated Prefrence option.
N/A
see also RFC3315
19.1.1. Creation and Transmission of Reconfigure Messages
21.5. Reconfigure Key Authentication Protocol
21.5.1. Use of the Authentication Option in the Reconfigure Key
Authentication Protocol
perldoc V6evalTool