Re: [anonsec] review comments on draft-ietf-btns-prob-and-applic-06.txt

Nicolas Williams <> Sat, 12 January 2008 00:16 UTC

Return-path: <>
Received: from [] ( by with esmtp (Exim 4.43) id 1JDU3L-0004Rt-DO for; Fri, 11 Jan 2008 19:16:47 -0500
Received: from ([]) by with esmtp (Exim 4.43) id 1JDU3K-00085h-SJ for; Fri, 11 Jan 2008 19:16:47 -0500
Received: from (localhost []) by (8.13.8/8.13.8) with ESMTP id m0C01fmT025712; Fri, 11 Jan 2008 16:01:41 -0800 (PST)
Received: from (brmea-mail-3.Sun.COM []) by (8.13.8/8.13.8) with ESMTP id m0C00PuS025319 for <>; Fri, 11 Jan 2008 16:00:26 -0800 (PST)
Received: from ([]) by (8.13.6+Sun/8.12.9) with ESMTP id m0C00Pv0005907 for <>; Sat, 12 Jan 2008 00:00:25 GMT
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM []) by (8.13.8+Sun/8.13.8/ENSMAIL, v2.2) with ESMTP id m0C00OVk049152 for <>; Fri, 11 Jan 2008 17:00:25 -0700 (MST)
Received: from binky.Central.Sun.COM (localhost []) by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m0C00KWo003009; Fri, 11 Jan 2008 18:00:20 -0600 (CST)
Received: (from nw141292@localhost) by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m0C00KGC003008; Fri, 11 Jan 2008 18:00:20 -0600 (CST)
X-Authentication-Warning: binky.Central.Sun.COM: nw141292 set sender to using -f
Date: Fri, 11 Jan 2008 18:00:20 -0600
From: Nicolas Williams <>
To: Stephen Kent <>
Message-ID: <20080112000019.GX810@Sun.COM>
Mail-Followup-To: Stephen Kent <>,,
References: <p0624051cc3a83920cdf2@[]>
Mime-Version: 1.0
Content-Disposition: inline
In-Reply-To: <p0624051cc3a83920cdf2@[]>
User-Agent: Mutt/1.5.7i
X-ISI-4-43-8-MailScanner: Found to be clean
Subject: Re: [anonsec] review comments on draft-ietf-btns-prob-and-applic-06.txt
X-Mailman-Version: 2.1.6
Precedence: list
List-Id: "Discussions of anonymous Internet security." <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Spam-Score: 0.0 (/)
X-Scan-Signature: b4a0a5f5992e2a4954405484e7717d8c

[I've taken the liberty of re-formatting the quoted text for line
wrapping and indentation.]

On Mon, Jan 07, 2008 at 03:18:09PM -0500, Stephen Kent wrote:
>        - creating IPsec/IKE SAs w/o authentication, for use in
>          contexts where an application will perform its own
>          authentication, but wants the layer 3 confidentiality,
>          integrity and continuity of authentication offered by ESP.
> 	   Here a critical part of the argument is that these
> 	   applications cannot use the authentication provided by IKE,
> 	   but the explanation for this is poor.

I think one part of the answer to this is there, but the other part
appears to be missing.

> 	                                         For example there is no
> 	   recognition of the use of EAP authentication methods with
> 	   IKE.

EAP is not applicable.  The applicability statement for EAP rules out
use where end-to-end authentication is desired.

Beyond that, the authentication infrastructure may not be suitable for
use in IKE, even if that's merely an issue of lack of specifications or
implementations.  (This is mentioned in the I-D.)

Finally, multi-user systems may need to authenticate individual users to
other entities, in which case IPsec is inapplicable[*].  (I cannot find
a mention of this in the I-D, not after a quick skim.)

[*] At least to my reading of RFC4301, though I see no reason why a
    system couldn't negotiate narrow SAs, each with different local IDs
    and credentials, with other peers.  But that wouldn't help
    applications that multiplex messages for many users' onto one TCP
    connection (e.g., NFS), in which case even if my readinf of RFC4301
    is wrong IPsec is still not applicable for authentication.

> 	        The text also does not address the possibility that a
> 	   suitable API could allow an application to acquire and track
> 	   the ID asserted during an IKE exchange, in lieu of the
> 	   unauthenticated SA approach that is being motivated.

Given the answers above such an API would be insufficient, though still
quite welcome.

Note that applications would care about the IDs of the SAs that protect
their packets.  But applications don't usually deal in packets.
Connection latching is a simple method for tracking the IDs of the SAs
that protect the apps' packets; the API that you suggest can be (and
will be) built on top of connection latching.  A non-connection-oriented
version of connection latching is certainly feasible too.

> The security considerations section is too long, mostly because much 
> of the material should be earlier, e.g., the CB discussion.  One 
> might also move the rekeying attack example (which I expanded to be 
> more accurate) to the CB document, and just reference the notion here.

Given that this is a problem and applicability statement for a security
technology, the security considerations section might as well state that
security considerations are discussed throughout the document, thus
freeing the authors to structure the document like you suggest.