Please take our Survey
logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

Re: Interoperability on RR BU Security?: msg#00033

ietf.mip6

Subject: Re: Interoperability on RR BU Security?

> => I have a concern with your question: it suggests there can be only two
> BU security techniques...

I think the question is more general, but occurs as soon as there are two
ways of doing something. Perhaps its not so critical in this case, but I
think it needs some thought now, in case a general negotiation mechanism is
required later.

> About the answer, with preconfig keys or IPsec, they are established
before
> the route optimization itself so the choice is clear (and BTW there cannot
> be a bidding down attack too). But the question is still open for other
> techniques so we can ask an answer for any other proposal?
>

So does the MN have a list of IP addresses with which it can do preconfig
keys? Is there some kind of API used to insert these addresses into the
Mobile IP code if a key is negotiated? It seems like there's an assumption
here that the MN has some kind of knowledge ahead of time that comes from
some unspecified source. I have a hard time understanding how this could
work in general.

In other protocols where both peers have a choice about how to perform some
kind of security operation, there are (sometimes elaborate) negotation
protocols to determine which choice to use. And, if down the line (doesn't
have to be right now), the WG has some interest or intention of approving
other, perhaps radically improved RO security mechanisms, I believe it would
be wise to consider the interoperability issue now when we are about to
approve a second, before we end up with a collection of RO security
mechanisms and no way to decide which one to use in any particular case. Or,
even worse, a collection of incompatible negotiation mechanisms.

As another data point, we decided in SEND to standardize just one
cryptosuite, RSA. We got some mildly negative IESG comment back about this,
but in the case of SEND, the interoperability issue is pretty critical, and
any kind of negotation would be really needless overhead on a fairly low
level operation which, while not done often, is performance critical when
done. If at some point there's problems with RSA, SEND would have to be
revised and a new technique standardized, with RSA becoming like the current
insecure ND, but that's OK because all evidence points to RSA being
sufficient for the indefinite future (with a mild concern about key length
growth as attacker processor power grows).

The RO security case isn't quite the same, because we already know that RR
isn't quite as secure as we would like and its performance isn't quite as
good as we would like, but if we are going to standardize another method,
even preconfig keys, the I think we need to think about interoperability.

'Nuff said.

jak


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
qplus.devel/200...    network.jabber....    debian.qa-packa...    encryption.gpg....    python.dabo.dev...    uclinux.devel/2...    science.mathema...    recreation.pesc...    kernel.ck/2004-...    mozilla.devel.e...    tex.latex.prosp...    ietf.multi6/200...    bbc.cvs/2002-11...    xfree86.newbie/...    jakarta.taglibs...    altlinux.hardwa...    comedi/2002-05/...    horde.bugs/2004...    games.diplomacy...    finance.e-gold....    web.dom.test-su...    lang.ruby.rails...    os.netbsd.devel...    video.gstreamer...   
Home | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe

Navigation