RE: IPSEC-PIB as mechanism for key distribution

<[email protected]> Thu, 15 Apr 2004 13:59:25 -0400
Newsgroups gmane.ietf.ipsp
Message-ID <A6D9D7495456414BA08DB655C2AC67120185BF93@bsebe001.americas.nokia.com>
You probably noticed that all the "key" attributes are optional. Hence, y=
ou don't have to use IPsec PIB to distribute keys. If you choose to distr=
ibute keys via IPsec PIB, you certainly need to secure the transport, i.e=
., COPS-PR protocol. These are discussed in the "security considerations"=
 section.

Best regards
Man Li

> -----Original Message-----
> From: [email protected]
> [mailto:[email protected]]On Behalf Of ext=20
> F=E9lix J.Garc=EDa
> Clemente
> Sent: Thursday, April 15, 2004 1:15 PM
> To: [email protected]
> Subject: IPSEC-PIB as mechanism for key distribution
>=20
>=20
>=20
>=20
> Hello all,
> IPSEC-PIB has several attributes to specify keys. The attribute
> ipSecXXTransformIntegrityKey specifies the integrity key to=20
> be used and
> the attribute ipSecEspTransformCipherKey specifies the cipher=20
> key to be
> used. And the attribute ipSecIkeAssociationPresharedKey contains the
> pre-shared key.
> It means that IPSEC-PIB is used to distribute keys, doesn't it?.
>=20
> I have noted that the keys don't have a specific class where can be
> defined (for example ipSecSharedSecret) and then they must be=20
> specified
> in other classes and it is not possible to reference them.
> Even the keys are transported by PIB in plaintext. Maybe an attribute
> similar to 'Algorithm' of the class CIM_SharedSecret may be useful to
> protect the keys.
> Maybe it can be interesting in a future draft. What do you think?
>=20
> Regards,
> F=E9lix
>=20
>=20
>=20
>=20