Re: Coding Of Public Signature Algorithm Identifier
Naohiro Fukuda <[email protected]> Tue, 14 Jan 2003 18:49:06 +0900
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
My name is Naohiro Fukuda, researching itrace. I have several questions, At 12:50 03/01/13 -0500, you wrote: >One piece of our proposed ITRACE record is a public signature algorithm >identifier. The identifiers I have been able to track down for this >purpose are in RFC 3279 (sec. 2.2), and take the form of OIDs. It seems a >pity to get so complicated for a handful of algorithms, but that may be >what we are stuck with unless we establish a registry of our own. I can >see these alternatives: > >1) use the OIDs. In that case, how do I specify the encoding in our >record: use only the value portion of the OID as encoded in ASN.1, or use >the entire ASN.1 object? > >2) specify the hash algorithm and the encryption algorithm as separate >items, concatenated. The hash algorithm can be the two-octet identifier >taken from the IANA IPSEC registry >(<http://www.iana.org/assignments/ipsec-registry>http://www.iana.org/assignments/ipsec-registry). >The encryption algorithm would probably best come from the two-octet >"IPSEC Authentication Methods" signature codepoints in the same registry >(i.e. codepoints 2, 3, and 8). Thus the complete signature algorithm >identifier would be a four-octet field. As I see the above 2), I am confusing now... Encryption can be applicable in the draft-ietf-itrace-02.txt?? My understanding of "2.8.3 Key Disclosure (TAG=0x0E) section" of draft-*-02.txt, the authentication of ICMP Traceback packet will be only applicable, it does not include encryption. Can we encrypt the Traceback packet with the key? I think it means the authentication algorithm of IPsec AH is aplicable, is it true? I think the draft says that it uses or borrows authentication algorithm(MD5,SHA1,...) and metod of IPsec AH(IANA's IDs), but it does not use IPsec AH to authenticate the ICMP traceback packet(s) itself. Correct? >3) establish our own list of signature algorithm identifiers, covering >the same ground as the RFC 3279 OIDs. > >Opinions? > >Tom Taylor >[email protected] >Ph. +1 613 736 0961 (ESN 396 1490) > Best Regards, ---------------------------------------------------------------------------------------- Naohiro Fukuda Matsushita Electric Works, Ltd. Network Security Team New Business Promotion Division Address: 5-13-2, Mita, Minato-ku, Tokyo 108-8351, Japan Tel: +81-3-3452-3390 Fax: +81-3-5442-9156 (MIC-TEL) :7-331-4856 (MIC-FAX) :7-331-4869 E-mail: [email protected] Homepage: http://www.nais-netcocoon.com ----------------------------------------------------------------------------------------