Please take our Survey
logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

Re: comments on draft-ietf-mip6-auth-protocol: msg#00152

ietf.mip6

Subject: Re: comments on draft-ietf-mip6-auth-protocol



Vijay.Devarapalli@xxxxxxxxx wrote:

section 6.1 doesnt talk about what the SPI should be set to.
Well, the SPI is the SPI of the SA, you are right, we may
need to add

clarifying text.

then I am confused with the role of SPI. in section 6.2 the SPI is
being used to differentiate between the use of CHAP or HMAC_CHAP.
it doesnt seem to be the SPI of the SA. is the role of SPI field
different depending on who (AAAH or HA) does the authentication?
6.0 describes the general meaning of spi. 6.1 (MN-HA auth option takes the meaning from there).
6.2, for MN-AAA auth option specifies the meaning of CHAP and HMAC_CHAP.

so it is used for different purporses in 6.1 and 6.2.(?)


Hope
that is clear?


nope. :(


Ok, in that case, we can add text clarifying the meaning of the various fields in
each, section 6.1 and 6.2 to make the distinction clear.

-a



8. Security Considerations

This document proposes new authentication options to authenticate the
control message between MN, HA and/or HAAA (as an
alternative to

IPsec). The new options provide for authentication
of Binding
Update
and Binding Acknowledgement messages



I think this section should say something about using the
same shared

key repeatedly. maybe it should recommend that a key
should be derived

from the shared key once in a while and the derived key
must be used
for
authenticating BU and BAck. (?)

Yes, I have revamped this section after talking with some security experts.
Mostly adding text clarifying the usage to keep the implementation secure.
due for next rev.

if you have the text ready, please post it. if we can review it now,
we could avoid one more revision of the draft.
I don't have an updated version. Can post is after IETF.


I meant just the text for the Security Considerations section. I wasnt looking for a new version of the draft. :)




<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
qplus.devel/200...    network.jabber....    debian.qa-packa...    encryption.gpg....    python.dabo.dev...    uclinux.devel/2...    science.mathema...    recreation.pesc...    kernel.ck/2004-...    mozilla.devel.e...    tex.latex.prosp...    ietf.multi6/200...    bbc.cvs/2002-11...    xfree86.newbie/...    jakarta.taglibs...    altlinux.hardwa...    comedi/2002-05/...    horde.bugs/2004...    games.diplomacy...    finance.e-gold....    web.dom.test-su...    lang.ruby.rails...    os.netbsd.devel...    video.gstreamer...   
Home | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe

Navigation