%% You should probably cite draft-wkumari-intarea-safe-limited-domains-06 instead of this revision. @techreport{wkumari-intarea-safe-limited-domains-05, number = {draft-wkumari-intarea-safe-limited-domains-05}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-wkumari-intarea-safe-limited-domains/05/}, author = {Warren Kumari and Andrew Alston and Éric Vyncke and Suresh Krishnan and Donald E. Eastlake 3rd}, title = {{Safe(r) Limited Domains}}, pagetotal = 12, year = , month = , day = , abstract = {Documents describing protocols that are only intended to be used within "limited domains" often do not clearly define how the boundary of the limited domain is implemented and enforced, or require that operators of these limited domains perfectly filter at all of the boundary nodes of the domain to protect the rest of the global Internet from these protocols and vice-versa. This document discusses some design principles and offers mechanisms to allow protocols that are designed to operate in a limited domain "fail-closed" rather than "fail-open", thereby making these protocols safer to deploy on the Internet. These mechanism are not applicable to all protocols intended for use in a limited domain, but if implemented on certain classes of protocols, they can significantly reduce the risks.}, }