RE: IPSEC-PIB as mechanism for key distribution
<[email protected]> Thu, 15 Apr 2004 13:59:25 -0400
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Message-ID | <A6D9D7495456414BA08DB655C2AC67120185BF93@bsebe001.americas.nokia.com> |
You probably noticed that all the "key" attributes are optional. Hence, y= ou don't have to use IPsec PIB to distribute keys. If you choose to distr= ibute keys via IPsec PIB, you certainly need to secure the transport, i.e= ., COPS-PR protocol. These are discussed in the "security considerations"= section. Best regards Man Li > -----Original Message----- > From: [email protected] > [mailto:[email protected]]On Behalf Of ext=20 > F=E9lix J.Garc=EDa > Clemente > Sent: Thursday, April 15, 2004 1:15 PM > To: [email protected] > Subject: IPSEC-PIB as mechanism for key distribution >=20 >=20 >=20 >=20 > Hello all, > IPSEC-PIB has several attributes to specify keys. The attribute > ipSecXXTransformIntegrityKey specifies the integrity key to=20 > be used and > the attribute ipSecEspTransformCipherKey specifies the cipher=20 > key to be > used. And the attribute ipSecIkeAssociationPresharedKey contains the > pre-shared key. > It means that IPSEC-PIB is used to distribute keys, doesn't it?. >=20 > I have noted that the keys don't have a specific class where can be > defined (for example ipSecSharedSecret) and then they must be=20 > specified > in other classes and it is not possible to reference them. > Even the keys are transported by PIB in plaintext. Maybe an attribute > similar to 'Algorithm' of the class CIM_SharedSecret may be useful to > protect the keys. > Maybe it can be interesting in a future draft. What do you think? >=20 > Regards, > F=E9lix >=20 >=20 >=20 >=20