RE: IPSEC-PIB as mechanism for key distribution

<[email protected]> Fri, 16 Apr 2004 10:40:15 -0400
Newsgroups gmane.ietf.ipsp
Message-ID <A6D9D7495456414BA08DB655C2AC6712015D239F@bsebe001.americas.nokia.com>
>=20
> > You probably noticed that all the "key" attributes are=20
> optional. Hence, you don't have to use IPsec PIB to distribute keys.
>=20
> Ok, but if IPsec PIB don't specify the keys, how can I know=20
> the keys to use?
> IPsec PIB cann't reference the keys. Do I must use a external=20
> mechanism to link the key with the PIB?

Yes.

>=20
> > If you choose to distribute keys via IPsec PIB, you=20
> certainly need to secure the transport, i.e., COPS-PR=20
> protocol. These are discussed in the "security=20
> considerations" section.
>=20
> Ok, I need to secure the transport protocol (maybe IPsec or=20
> TLS) and then it means that I need distribute keys previously.
> In my opinion, I think the key distribution must be not=20
> permited in the IPsec PIB (neither as optional) and other=20
> mechanism has to be used to distribute keys (maybe other PIB or MIB).

Many other people have different opinions than yours and that's why we ha=
ve the optional feature. =20

>=20
> Regards,
> F=E9lix
>=20
> > Best regards
> > Man Li
> >
> > > -----Original Message-----
> > > From: [email protected]
> > > [mailto:[email protected]]On Behalf Of ext
> > > F=E9lix J.Garc=EDa
> > > Clemente
> > > Sent: Thursday, April 15, 2004 1:15 PM
> > > To: [email protected]
> > > Subject: IPSEC-PIB as mechanism for key distribution
> > >
> > >
> > >
> > >
> > > Hello all,
> > > IPSEC-PIB has several attributes to specify keys. The attribute
> > > ipSecXXTransformIntegrityKey specifies the integrity key to
> > > be used and
> > > the attribute ipSecEspTransformCipherKey specifies the cipher
> > > key to be
> > > used. And the attribute ipSecIkeAssociationPresharedKey=20
> contains the
> > > pre-shared key.
> > > It means that IPSEC-PIB is used to distribute keys, doesn't it?.
> > >
> > > I have noted that the keys don't have a specific class=20
> where can be
> > > defined (for example ipSecSharedSecret) and then they must be
> > > specified
> > > in other classes and it is not possible to reference them.
> > > Even the keys are transported by PIB in plaintext. Maybe=20
> an attribute
> > > similar to 'Algorithm' of the class CIM_SharedSecret may=20
> be useful to
> > > protect the keys.
> > > Maybe it can be interesting in a future draft. What do you think?
> > >
> > > Regards,
> > > F=E9lix
> > >
> > >
> > >
> > >
>=20
>=20
>=20