#329939 dhcp3-client: please expand security-related options (such as reject) to accept networks

Package:
isc-dhcp-client
Source:
isc-dhcp
Description:
DHCP client for automatically obtaining an IP address
Submitter:
Henrique de Moraes Holschuh
Date:
2026-08-05 17:33:24 UTC
Severity:
wishlist
#329939#5
Date:
2005-09-24 15:30:18 UTC
From:
To:
Some of us have to use dhcp3-client to tie to very, very hostile networks,
such as ADSL or cable.  The DHCP server on these networks often migrate
without warning, so we never know from which IP the answer will come.

It would be *very* handy to be able to:

reject 10.0.0.0/8 192.168.0.0/16 172.16.0.0/12 169.254.0.0/16;

to at least reject all rogue DHCP servers caused by morons in the local
cable/ADSL network (which IS quite common), and fucked up cable modems that
are non-configurable and try to give you broken addresses when the cable is
down (which is even more common than morons with DHCP servers, at least here
in Brazil).  It won't get real attacks, but these are very very rare.

Obviously there is absolutely no acceptable way to do this on dhclient3
currently.  Packet filter rules must be used on the prerouting chain...
which is ugly at best.

#329939#8
Date:
2005-10-06 11:35:21 UTC
From:
To:
Hi,

I received this wishlist bug report from a dhclient user the other day.

Seems like a fairly reasonable request to me.

Please maintain the Cc so that the submitter and the BTS are kept in the
loop.

regards

Andrew

#329939#9
Date:
2005-10-06 17:21:54 UTC
From:
To:
there's no shortage of packages that implement allow/deny in configuration files
from which to copy the code.

#329939#10
Date:
2005-10-06 19:59:51 UTC
From:
To:
There is a 'reject subnet' patch on the dhcp-suggest queue already for
3.1.0 consideration which basically does this.

And still doesn't solve the problem, since server addresses are easily
spoofable (give out a giant lease time and you don't have to worry about
renewals, the client digests your bad options forever).

Server/client authentication and authorization need to become commonplace,
somehow.

#329939#11
Date:
2008-01-15 04:44:38 UTC
From:
To:
Hello,

This bug was received some time ago, and I forwarded it on to
dhcp-hackers, because I wasn't aware of dhcp-bugs at the time.

I'm reforwarding it as an upstream bug so it gets tracked properly.

Please maintain the Cc on correspondence to keep our bug tracking system
in the loop.

regards

Andrew
----- Forwarded message from Henrique de Moraes Holschuh <hmh@debian.org> ----- Subject: Bug#329939: dhcp3-client: please expand security-related options (such as reject) to accept networks Reply-To: Henrique de Moraes Holschuh <hmh@debian.org>, 329939@bugs.debian.org Resent-From: Henrique de Moraes Holschuh <hmh@debian.org> Resent-To: debian-bugs-dist@lists.debian.org Resent-CC: peloy@debian.org (Eloy A. Paris) Resent-Date: Sat, 24 Sep 2005 15:33:07 UTC Resent-Message-ID: <handler.329939.B.112757582226154@bugs.debian.org> Resent-Sender: owner@bugs.debian.org X-Debian-PR-Message: report 329939 X-Debian-PR-Package: dhcp3-client X-Debian-PR-Keywords: From: Henrique de Moraes Holschuh <hmh@debian.org> To: Debian Bug Tracking System <submit@bugs.debian.org> X-Reportbug-Version: 3.17 X-GPG-Fingerprint: 1024D/1CDB0FE3 5422 5C61 F6B7 06FB 7E04 3738 EE25 DE3F 1CDB 0FE3 X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at khazad-dum.debian.net X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Level: X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE autolearn=no version=2.60-bugs.debian.org_2005_01_02 Package: dhcp3-client Version: 3.0.3-3 Severity: wishlist Some of us have to use dhcp3-client to tie to very, very hostile networks, such as ADSL or cable. The DHCP server on these networks often migrate without warning, so we never know from which IP the answer will come. It would be *very* handy to be able to: reject 10.0.0.0/8 192.168.0.0/16 172.16.0.0/12 169.254.0.0/16; to at least reject all rogue DHCP servers caused by morons in the local cable/ADSL network (which IS quite common), and fucked up cable modems that are non-configurable and try to give you broken addresses when the cable is down (which is even more common than morons with DHCP servers, at least here in Brazil). It won't get real attacks, but these are very very rare. Obviously there is absolutely no acceptable way to do this on dhclient3 currently. Packet filter rules must be used on the prerouting chain... which is ugly at best.
----- End forwarded message -----
#329939#22
Date:
2026-08-05 17:31:09 UTC
From:
To:
Dear submitter,

as the package isc-dhcp has just been removed from the Debian archive
unstable we hereby close the associated bug reports.  We are sorry
that we couldn't deal with your issue properly.

For details on the removal, please see https://bugs.debian.org/1143544

The version of this package that was in Debian prior to this removal
can still be found using https://snapshot.debian.org/.

Please note that the changes have been done on the master archive and
will not propagate to any mirrors until the next dinstall run at the
earliest.

This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
ftpmaster@ftp-master.debian.org.

Debian distribution maintenance software
pp.
Thorsten Alteholz (the ftpmaster behind the curtain)