Re: Coding Of Public Signature Algorithm Identifier
"Marcus Leech" <[email protected]> Tue, 14 Jan 2003 12:54:31 -0500
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Nortel Networks |
| Message-ID | <[email protected]> |
Naohiro Fukuda wrote: > > > As I see the above 2), I am confusing now... Encryption can be applicable in the > draft-ietf-itrace-02.txt?? > > My understanding of "2.8.3 Key Disclosure (TAG=0x0E) section" of draft-*-02.txt, the > authentication of ICMP > Traceback packet will be only applicable, it does not include encryption. > > Can we encrypt the Traceback packet with the key? > I think it means the authentication algorithm of IPsec AH is aplicable, is it true? > > I think the draft says that it uses or borrows authentication algorithm(MD5,SHA1,...) > and metod of IPsec AH(IANA's IDs), > but it does not use IPsec AH to authenticate the ICMP traceback packet(s) itself. > > Correct? ITRACE doesn't encrypt any data, but we're talking about borrowing some of the codepoints that IPSEC uses to indicate hash algorithm choices, that's all. Similarly, for public-key algorithms, we need to be able to indicate which algorithm is in use, and that is what Toms question is about. -- ---------------------------------------------------------------------- Marcus Leech Mail: Dept 8M70, MS 012, FITZ Advisor Phone: (ESN) 393-9145 +1 613 763 9145 Security Architecture and Planning Fax: (ESN) 393-9435 +1 613 763 9435 Nortel Networks [email protected] -----------------Expressed opinions are my own, not my employer's------