[dhcwg] IPsec for DHCPv6 client ?

Jean-Mickael Guerin <jean-mickael.guerin@6wind.com> Mon, 09 September 2002 13:53 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA01908 for <dhcwg-archive@odin.ietf.org>; Mon, 9 Sep 2002 09:53:47 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id g89DtAk11356 for dhcwg-archive@odin.ietf.org; Mon, 9 Sep 2002 09:55:10 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id g89Dt9711353 for <dhcwg-web-archive@optimus.ietf.org>; Mon, 9 Sep 2002 09:55:09 -0400
Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA01884 for <dhcwg-web-archive@ietf.org>; Mon, 9 Sep 2002 09:53:16 -0400 (EDT)
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id g89Dq6711083; Mon, 9 Sep 2002 09:52:06 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id g89DoD709997 for <dhcwg@optimus.ietf.org>; Mon, 9 Sep 2002 09:50:13 -0400
Received: from proxy.6wind.com (proxy.6wind.com [194.250.197.211]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA29805 for <dhcwg@ietf.org>; Mon, 9 Sep 2002 08:54:03 -0400 (EDT)
Received: from intranet.6wind.com (intranet [10.0.0.113]) by proxy.6wind.com (Postfix) with ESMTP id 62A9C3EF for <dhcwg@ietf.org>; Mon, 9 Sep 2002 15:00:23 +0200 (CEST)
Received: from 6wind.com (unknown [10.16.0.134]) by intranet.6wind.com (Postfix) with ESMTP id C845EB4FA for <dhcwg@ietf.org>; Mon, 9 Sep 2002 14:53:36 +0200 (CEST)
Message-ID: <3D7C9A23.2080701@6wind.com>
Date: Mon, 09 Sep 2002 14:54:59 +0200
From: Jean-Mickael Guerin <jean-mickael.guerin@6wind.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; fr-FR; rv:0.9.4.1) Gecko/20020508 Netscape6/6.2.3
X-Accept-Language: fr-fr
MIME-Version: 1.0
To: dhcwg@ietf.org
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Subject: [dhcwg] IPsec for DHCPv6 client ?
Sender: dhcwg-admin@ietf.org
Errors-To: dhcwg-admin@ietf.org
X-BeenThere: dhcwg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=unsubscribe>
List-Id: <dhcwg.ietf.org>
List-Post: <mailto:dhcwg@ietf.org>
List-Help: <mailto:dhcwg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

Hello,

I have a question about security mechanisms proposed in the draft, 
hoping it has not be discussed before, in case I'd appreciate pointers. 
The delayed authentication uses a shared secret and considers mainly 
intradomain roaming. IPsec is proposed between relays and servers 
because they're likely to belong to the same administrative domain.
Why is not proposed using IPsec to secure communications between clients 
and servers with the some restrictions, i.e. installation of static keys 
as shared secret, in intra-domain ?


Regards,

-- 

Jean-Mickael GUERIN
Tel : +33 1 39 30 92 33
Web site : www.6wind.com

_______________________________________________
dhcwg mailing list
dhcwg@ietf.org
https://www1.ietf.org/mailman/listinfo/dhcwg