Re: Coding Of Public Signature Algorithm Identifier

"Marcus Leech" <[email protected]> Tue, 14 Jan 2003 12:54:31 -0500
Newsgroups gmane.ietf.itrace
Organization Nortel Networks
Message-ID <[email protected]>
Naohiro Fukuda wrote:
> 
> 
> As I see the above 2), I am confusing now... Encryption can be applicable in the
> draft-ietf-itrace-02.txt??
> 
> My understanding of  "2.8.3 Key Disclosure (TAG=0x0E) section" of draft-*-02.txt, the
> authentication of ICMP
> Traceback packet will be only applicable, it does not include encryption.
> 
> Can we encrypt the Traceback packet with the key?
> I think it means the authentication algorithm of IPsec AH is aplicable, is it true?
> 
> I think the draft says that it uses or borrows authentication algorithm(MD5,SHA1,...)
> and metod of IPsec AH(IANA's IDs),
>  but it does not use IPsec AH to authenticate the ICMP traceback packet(s) itself.
> 
> Correct?
ITRACE doesn't encrypt any data, but we're talking about borrowing some of the
  codepoints that IPSEC uses to indicate hash algorithm choices, that's all.

Similarly, for public-key algorithms, we need to be able to indicate which
  algorithm is in use, and that is what Toms question is about.

-- 
----------------------------------------------------------------------
Marcus Leech                             Mail:   Dept 8M70, MS 012, FITZ
Advisor                                  Phone: (ESN) 393-9145  +1 613 763 9145
Security Architecture and Planning       Fax:   (ESN) 393-9435  +1 613 763 9435
Nortel Networks                          [email protected]
-----------------Expressed opinions are my own, not my employer's------