FeatureFuel
2

Allow smaller subnets than /64 for security.ipv6_normalized_subnet_size

Source: nextcloud/server#57650 · opened by @erbth
Allow smaller subnets than /64 for security.ipv6_normalized_subnet_size: If one operates a network for client devices with a single /64 IPv6 prefix and SLAAC, a single client using wrong passwords can impact all clients of the network. This cannot be mitigated at the moment, because security.ipv6_normalized_subnet_size will clamp values larger than 64 to 64. Consider e.g. a wifi-network with a /64 IPv6 range and SLAAC. If one smartphone in that network has an outdated password stored in a calendar client, the entire /64 might be blocked, leading to delayed requests (due to throttling) for all other clients in that wifi network...

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests