RE: IPSEC-PIB as mechanism for key distribution
<[email protected]> Fri, 16 Apr 2004 10:40:15 -0400
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Message-ID | <A6D9D7495456414BA08DB655C2AC6712015D239F@bsebe001.americas.nokia.com> |
>=20 > > You probably noticed that all the "key" attributes are=20 > optional. Hence, you don't have to use IPsec PIB to distribute keys. >=20 > Ok, but if IPsec PIB don't specify the keys, how can I know=20 > the keys to use? > IPsec PIB cann't reference the keys. Do I must use a external=20 > mechanism to link the key with the PIB? Yes. >=20 > > If you choose to distribute keys via IPsec PIB, you=20 > certainly need to secure the transport, i.e., COPS-PR=20 > protocol. These are discussed in the "security=20 > considerations" section. >=20 > Ok, I need to secure the transport protocol (maybe IPsec or=20 > TLS) and then it means that I need distribute keys previously. > In my opinion, I think the key distribution must be not=20 > permited in the IPsec PIB (neither as optional) and other=20 > mechanism has to be used to distribute keys (maybe other PIB or MIB). Many other people have different opinions than yours and that's why we ha= ve the optional feature. =20 >=20 > Regards, > F=E9lix >=20 > > Best regards > > Man Li > > > > > -----Original Message----- > > > From: [email protected] > > > [mailto:[email protected]]On Behalf Of ext > > > F=E9lix J.Garc=EDa > > > Clemente > > > Sent: Thursday, April 15, 2004 1:15 PM > > > To: [email protected] > > > Subject: IPSEC-PIB as mechanism for key distribution > > > > > > > > > > > > > > > Hello all, > > > IPSEC-PIB has several attributes to specify keys. The attribute > > > ipSecXXTransformIntegrityKey specifies the integrity key to > > > be used and > > > the attribute ipSecEspTransformCipherKey specifies the cipher > > > key to be > > > used. And the attribute ipSecIkeAssociationPresharedKey=20 > contains the > > > pre-shared key. > > > It means that IPSEC-PIB is used to distribute keys, doesn't it?. > > > > > > I have noted that the keys don't have a specific class=20 > where can be > > > defined (for example ipSecSharedSecret) and then they must be > > > specified > > > in other classes and it is not possible to reference them. > > > Even the keys are transported by PIB in plaintext. Maybe=20 > an attribute > > > similar to 'Algorithm' of the class CIM_SharedSecret may=20 > be useful to > > > protect the keys. > > > Maybe it can be interesting in a future draft. What do you think? > > > > > > Regards, > > > F=E9lix > > > > > > > > > > > > >=20 >=20 >=20