Re: IPSEC-PIB as mechanism for key distribution
"Félix J.García Clemente" <[email protected]> Fri, 16 Apr 2004 10:38:52 +0200
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Message-ID | <[email protected]> |
Hello, [email protected] wrote: > You probably noticed that all the "key" attributes are optional. Hence,= you don't have to use IPsec PIB to distribute keys. Ok, but if IPsec PIB don't specify the keys, how can I know the keys to u= se? IPsec PIB cann't reference the keys. Do I must use a external mechanism t= o link the key with the PIB? > If you choose to distribute keys via IPsec PIB, you certainly need to s= ecure the transport, i.e., COPS-PR protocol. These are discussed in the "= security considerations" section. Ok, I need to secure the transport protocol (maybe IPsec or TLS) and then= it means that I need distribute keys previously. In my opinion, I think the key distribution must be not permited in the I= Psec PIB (neither as optional) and other mechanism has to be used to dist= ribute keys (maybe other PIB or MIB). Regards, F=E9lix > Best regards > Man Li > > > -----Original Message----- > > From: [email protected] > > [mailto:[email protected]]On Behalf Of ext > > F=E9lix J.Garc=EDa > > Clemente > > Sent: Thursday, April 15, 2004 1:15 PM > > To: [email protected] > > Subject: IPSEC-PIB as mechanism for key distribution > > > > > > > > > > Hello all, > > IPSEC-PIB has several attributes to specify keys. The attribute > > ipSecXXTransformIntegrityKey specifies the integrity key to > > be used and > > the attribute ipSecEspTransformCipherKey specifies the cipher > > key to be > > used. And the attribute ipSecIkeAssociationPresharedKey contains the > > pre-shared key. > > It means that IPSEC-PIB is used to distribute keys, doesn't it?. > > > > I have noted that the keys don't have a specific class where can be > > defined (for example ipSecSharedSecret) and then they must be > > specified > > in other classes and it is not possible to reference them. > > Even the keys are transported by PIB in plaintext. Maybe an attribute > > similar to 'Algorithm' of the class CIM_SharedSecret may be useful to > > protect the keys. > > Maybe it can be interesting in a future draft. What do you think? > > > > Regards, > > F=E9lix > > > > > > > >