RE: Status of Seamoby drafts
Nakhjiri Madjid-MNAKHJI1 <[email protected]> Wed, 21 Jul 2004 15:26:46 -0500
| Newsgroups | gmane.ietf.seamoby |
|---|---|
| Message-ID | <[email protected]> |
Hi, I am trying to understand what we are debating: a) The assumption of pre-established shared secret for IKE between ARs is not practical? You should not go through a burden of shared secret configuration, and should use certificates? or b) IKE is not practical? and some other key exchange/ SA management method must be used. Answer to a) The way I see it, doing IKE just in time for CTP is not practical, since the round trip delays involved in IKE defeats the purpose of CTP for enhancing the handover in the first place. IF you decide on IKE, it has to be done way before the handover and between each AR-pair. It does not matter whether you are using shared secrets or certificates, you are not saving any round trips. You just have less administrative burden with certificates, but more investment requirement for the PKI that you have to put in place. Answer to b) This is a completely separate issues. Then you have to see whether you want to use IPsec or something else like TLS (which means setting up TCP between AR, and we don't want that) or some other security method. When you decide IPsec, then you need to find an implementation that does IPsec without IKE (not sure how common that is). >From the discussions I have seen, it is not clear what we are debating? Regards, Madjid -----Original Message----- From: [email protected] [mailto:[email protected]]On Behalf Of James Kempf Sent: Friday, July 16, 2004 5:52 PM To: [email protected]; Vijay Devarapalli Cc: [email protected] Subject: Re: [Seamoby] Status of Seamoby drafts I think that if each router shares a symmetric security association with each other router, secured by a shared key, and there are n routers, the total number of keys is sum i over n-1 to 0 ( i ). 5 routers require 4 + 3 + 2 +1 keys, 3 routers require 2 + 1 keys, etc. I agree that it is a lot less than n(n-1), I don't know where he got that number. I think the point he is trying to make is that a symmetric keying scheme would result in a configuration problem for a large network. But my response to him is that it isn't a problem for this document to solve, at least, not yet. I don't think we need to engage him on the accuracy of his estimate. jak ----- Original Message ----- From: "Rajeev Koodli" <[email protected]> To: "Vijay Devarapalli" <[email protected]> Cc: "James Kempf" <[email protected]>; <[email protected]> Sent: Friday, July 16, 2004 3:23 PM Subject: Re: [Seamoby] Status of Seamoby drafts > > Vijay, Jim, > > Vijay Devarapalli wrote: > > > > Since context transfer security is an n by n problem, establishing the SAs > > > to protect inter-router transfers is not an easy thing. For this reason one > > > might conclude that pre-shared keys are difficult, since n(n-1) of them > > > would be necessary. On the other hand, is it being suggested that each > > > router needs to be provisioned with a certificate? On reading the draft it > > > isn't clear what's being recommended (or even considered). > > > > I could not parse the "n by n" problem. Any pointers ? > Why is the order higher than pairwise SA between routers, which might > already exist ? > > -Rajeev > > > > > > this comment is valid. but since we assume the access routers are > > part of the same administrative domain, they are provisioned with > > the required certificates to run IKE. (?) > > > > Vijay > > > > _______________________________________________ > > Seamoby mailing list > > [email protected] > > https://www1.ietf.org/mailman/listinfo/seamoby > > _______________________________________________ Seamoby mailing list [email protected] https://www1.ietf.org/mailman/listinfo/seamoby