Re: IPSEC-PIB as mechanism for key distribution

"Félix J.García Clemente" <[email protected]> Fri, 16 Apr 2004 10:38:52 +0200
Newsgroups gmane.ietf.ipsp
Message-ID <[email protected]>
Hello,

[email protected] wrote:

> You probably noticed that all the "key" attributes are optional. Hence,=
 you don't have to use IPsec PIB to distribute keys.

Ok, but if IPsec PIB don't specify the keys, how can I know the keys to u=
se?
IPsec PIB cann't reference the keys. Do I must use a external mechanism t=
o link the key with the PIB?

> If you choose to distribute keys via IPsec PIB, you certainly need to s=
ecure the transport, i.e., COPS-PR protocol. These are discussed in the "=
security considerations" section.

Ok, I need to secure the transport protocol (maybe IPsec or TLS) and then=
 it means that I need distribute keys previously.
In my opinion, I think the key distribution must be not permited in the I=
Psec PIB (neither as optional) and other mechanism has to be used to dist=
ribute keys (maybe other PIB or MIB).

Regards,
F=E9lix

> Best regards
> Man Li
>
> > -----Original Message-----
> > From: [email protected]
> > [mailto:[email protected]]On Behalf Of ext
> > F=E9lix J.Garc=EDa
> > Clemente
> > Sent: Thursday, April 15, 2004 1:15 PM
> > To: [email protected]
> > Subject: IPSEC-PIB as mechanism for key distribution
> >
> >
> >
> >
> > Hello all,
> > IPSEC-PIB has several attributes to specify keys. The attribute
> > ipSecXXTransformIntegrityKey specifies the integrity key to
> > be used and
> > the attribute ipSecEspTransformCipherKey specifies the cipher
> > key to be
> > used. And the attribute ipSecIkeAssociationPresharedKey contains the
> > pre-shared key.
> > It means that IPSEC-PIB is used to distribute keys, doesn't it?.
> >
> > I have noted that the keys don't have a specific class where can be
> > defined (for example ipSecSharedSecret) and then they must be
> > specified
> > in other classes and it is not possible to reference them.
> > Even the keys are transported by PIB in plaintext. Maybe an attribute
> > similar to 'Algorithm' of the class CIM_SharedSecret may be useful to
> > protect the keys.
> > Maybe it can be interesting in a future draft. What do you think?
> >
> > Regards,
> > F=E9lix
> >
> >
> >
> >