Re: Proposal for revised charter

"Ariel Shaqed (Scolnicov)" <[email protected]> Tue, 11 Apr 2006 09:45:20 +0300
Newsgroups gmane.ietf.mobike
Organization Check Point Software Technologies
Message-ID <200604110945.23467@kmail-ckp>
On Tuesday 11 April 2006 00:22, Julien Laganier wrote:
> Hi Yaron,
>
> I have few questions on your rechartering proposal.
>
> On Monday 10 April 2006 15:04, Yaron Sheffer wrote:
> > I realize that I'm a bit late, but still...
> >
> > I would like to propose two work items that I believe fall within
> > MOBIKE's charter.
>
> <snip>
>
> > 2. Short-term credentials assigned by one gateway, to allow a
> > client to connect to another gateway without performing full
> > EAP-based authentication (and entering a password). Although the
> > need to connect to multiple IPsec gateways is not limited to the
> > mobility case, it is amplified by mobility. For example, some of
> > the gateways may not be accessible through different access
> > methods, e.g. cellular/GPRS.
>
> What kind of short term credentials do you have in mind? Pre-shared
> key? Or certificates?
>
> Also, IIUC that would means that the keying material required to
> validate those credentials would need to be distributed amongst the
> multiple gateways. Would you like to include such a work item in
> MOBIKE charter?
>
> Finally, I guess the goal of your proposal is to reduce the delay of
> establishment of secure access upon inter-technology handover, right?
> Don't you think this goal could be achieved more simply via
> pre-authentication to the next gateway while still attached to the
> old gateway?

Key exchange and authentication are distinct in remote access, even though 
they may occur in the same process.  During roaming, you may need to 
exchange keys even if there is no need to re-authenticate.

In many remote access scenarios, there is more to the handover than just 
delay.  Some popular authentication technologies require user intervention 
to succeed.  It would be desirable to provide an alternative to users 
having to re-enter credentials, e.g. from some token.  Pre-authentication 
actually makes this worse, as the user's work is potentially wasted.

>
> Thanks. Best regards,
>
> --julien
>
> > -----Original Message-----
> > From: Paul Hoffman [mailto:[email protected]]
> > Sent: Friday, April 7, 2006 18:54
> > To: [email protected]
> > Cc: Russ Housley
> > Subject: Re: [Mobike] Proposal for revised charter
> >
> > There seems to be not enough interest in the WG to revise the
> > charter: only two people spoke up. I assume that the people at the
> > face-to-face meeting who wanted to see the charter revised wanted
> > to see the work done, but didn't intend to help do it, which is
> > understandable.
> >
> > <cue the forlorn violin music>
> >
> > Russ: please start the process to shut down the MOBIKE WG. I assume
> > that Steve Bellovin, our mailing list host, will keep the list open
> > indefinitely. If not, we can move it to VPNC.
> >
> > --Paul Hoffman, Director
> > --VPN Consortium
> >
> >
> > _______________________________________________
> > Mobike mailing list
> > [email protected]
> > https://www.machshav.com/mailman/listinfo.cgi/mobike
>
> _______________________________________________
> Mobike mailing list
> [email protected]
> https://www.machshav.com/mailman/listinfo.cgi/mobike