SPI collision Re: FW: Tuomas Aura's review of draft-ietf-mobike-protocol-03

"Mohan Parthasarathy" <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <00b701c5ce06$562c5a00$6501a8c0@adithya>
Tero,

> >Comment 4: 
> >
> >IPsec SAs are identified by the <destination IP address, SPI> pair.
> >Normally, these identifiers are unique for inbound SAs destination
> >host is responsible for allocating the SPIs and for outbound SAs
> >because the destination address identifies a unique host. In
> >Mobike, the latter is no longer true. That is, identifier
> >collisions may occur for outbound SAs at the responder.
> 
> ESPv3 the IPsec SA is identified by the SPI alone for the unicast SAs.
> There is no destination IP address threre anymore. Implementations are
> allowed to use SPI and IPsec protocol type also.
> (draft-ietf-ipsec-esp-v3-10.txt section 2.1).
> 
Yes, but that concerns inbound processing. Here we are talking about outbound
processing i thought.

> >Consider the following example of an accidental collision: I1 and
> >I2 are honest initiators that both have an SA with the same honest
> >responder R. The outbound SAs from R happen, by change, to have the
> >same SPI. (This is ok because the destination IP addresses differ.)
> 
> This is not ok with the mobike, as it requires IKEv2, which requires
> RFC2401bis, which requires ESPv3...
>
Are you saying that this problem cannot happen ? The I1 and I2 are two
different hosts and they *can* choose the same SPI. When R is sending
packets to I1 or I2, it does not use the SPI for lookup. It uses the selectors
from the packet to lookup the SA. The selectors are unique (they are still I1
plus whatever the policy requires) even after I1 moves to A2. But this leads
to two SAs with the same SPI. This should not cause any problem (in theory)
because you never lookup this SA directly. You always lookup the SPD which
points to the SA. But there are implementations (e.g. Linux) where this can cause
problems if you update an SA that will result in the same values (dest address, SPI,
protocol) as another SA. So, can you clarify ?

-mohan

> -- 
> [email protected]
> _______________________________________________
> Mobike mailing list
> [email protected]
> https://www.machshav.com/mailman/listinfo.cgi/mobike
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.