#329939 dhcp3-client: please expand security-related options (such as reject) to accept networks #329939
- Package:
- isc-dhcp-client
- Source:
- isc-dhcp
- Description:
- DHCP client for automatically obtaining an IP address
- Submitter:
- Henrique de Moraes Holschuh
- Date:
- 2026-08-05 17:33:24 UTC
- Severity:
- wishlist
Some of us have to use dhcp3-client to tie to very, very hostile networks, such as ADSL or cable. The DHCP server on these networks often migrate without warning, so we never know from which IP the answer will come. It would be *very* handy to be able to: reject 10.0.0.0/8 192.168.0.0/16 172.16.0.0/12 169.254.0.0/16; to at least reject all rogue DHCP servers caused by morons in the local cable/ADSL network (which IS quite common), and fucked up cable modems that are non-configurable and try to give you broken addresses when the cable is down (which is even more common than morons with DHCP servers, at least here in Brazil). It won't get real attacks, but these are very very rare. Obviously there is absolutely no acceptable way to do this on dhclient3 currently. Packet filter rules must be used on the prerouting chain... which is ugly at best.
Hi, I received this wishlist bug report from a dhclient user the other day. Seems like a fairly reasonable request to me. Please maintain the Cc so that the submitter and the BTS are kept in the loop. regards Andrew
there's no shortage of packages that implement allow/deny in configuration files from which to copy the code.
There is a 'reject subnet' patch on the dhcp-suggest queue already for 3.1.0 consideration which basically does this. And still doesn't solve the problem, since server addresses are easily spoofable (give out a giant lease time and you don't have to worry about renewals, the client digests your bad options forever). Server/client authentication and authorization need to become commonplace, somehow.
Hello, This bug was received some time ago, and I forwarded it on to dhcp-hackers, because I wasn't aware of dhcp-bugs at the time. I'm reforwarding it as an upstream bug so it gets tracked properly. Please maintain the Cc on correspondence to keep our bug tracking system in the loop. regards Andrew----- Forwarded message from Henrique de Moraes Holschuh <hmh@debian.org> ----- Subject: Bug#329939: dhcp3-client: please expand security-related options (such as reject) to accept networks Reply-To: Henrique de Moraes Holschuh <hmh@debian.org>, 329939@bugs.debian.org Resent-From: Henrique de Moraes Holschuh <hmh@debian.org> Resent-To: debian-bugs-dist@lists.debian.org Resent-CC: peloy@debian.org (Eloy A. Paris) Resent-Date: Sat, 24 Sep 2005 15:33:07 UTC Resent-Message-ID: <handler.329939.B.112757582226154@bugs.debian.org> Resent-Sender: owner@bugs.debian.org X-Debian-PR-Message: report 329939 X-Debian-PR-Package: dhcp3-client X-Debian-PR-Keywords: From: Henrique de Moraes Holschuh <hmh@debian.org> To: Debian Bug Tracking System <submit@bugs.debian.org> X-Reportbug-Version: 3.17 X-GPG-Fingerprint: 1024D/1CDB0FE3 5422 5C61 F6B7 06FB 7E04 3738 EE25 DE3F 1CDB 0FE3 X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at khazad-dum.debian.net X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Level: X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE autolearn=no version=2.60-bugs.debian.org_2005_01_02 Package: dhcp3-client Version: 3.0.3-3 Severity: wishlist Some of us have to use dhcp3-client to tie to very, very hostile networks, such as ADSL or cable. The DHCP server on these networks often migrate without warning, so we never know from which IP the answer will come. It would be *very* handy to be able to: reject 10.0.0.0/8 192.168.0.0/16 172.16.0.0/12 169.254.0.0/16; to at least reject all rogue DHCP servers caused by morons in the local cable/ADSL network (which IS quite common), and fucked up cable modems that are non-configurable and try to give you broken addresses when the cable is down (which is even more common than morons with DHCP servers, at least here in Brazil). It won't get real attacks, but these are very very rare. Obviously there is absolutely no acceptable way to do this on dhclient3 currently. Packet filter rules must be used on the prerouting chain... which is ugly at best.----- End forwarded message -----
Dear submitter, as the package isc-dhcp has just been removed from the Debian archive unstable we hereby close the associated bug reports. We are sorry that we couldn't deal with your issue properly. For details on the removal, please see https://bugs.debian.org/1143544 The version of this package that was in Debian prior to this removal can still be found using https://snapshot.debian.org/. Please note that the changes have been done on the master archive and will not propagate to any mirrors until the next dinstall run at the earliest. This message was generated automatically; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org. Debian distribution maintenance software pp. Thorsten Alteholz (the ftpmaster behind the curtain)