[Hipsec-rg] 答复: Key Revocation Issue
zhangdacheng at huawei.com (Zhang Dacheng) Wed, 21 January 2009 09:00 UTC
From: "zhangdacheng at huawei.com"
Date: Wed, 21 Jan 2009 17:00:49 +0800
Subject: [Hipsec-rg] 答复: Key Revocation Issue
In-Reply-To: <4976D726.5020508@hiit.fi>
Message-ID: <001a01c97ba6$c1e04da0$480c6f0a@china.huawei.com>
Hi: DNS server cannot directly be used to help a user holding a antique HIT access the host whose HIT has been changed, unless the user has got the FQDN (by reverse DNS lookup of HITs maybe) in advance. Additional authentication processes are needed too, and so DNS can guarantee only the owner of a HIT can modify its result. Another concern is that should we assume that every host using HIT should be registered with DNS? > > Zhang Dacheng wrote: > > Hi, > > > Hello everyone: > > > > When reading IETF HIP related documents, I found there were > still lots > > of things left for us to explore in the key revocation > issues. Because > > of security reasons, the cryptographic key held by a host normally > > should be changed after being used for a certain period. In > this case, > > the HIT needs to be changed too. > > > > Assume there is a host, A, which has changed its HIT. It may be not > > practical for A to notify all the hosts which hold the old HIT of A > > about the change, and this can cause several problems. For example, > > when A attempts to use the new HIT to access a server which > uses the > > old HIT of A in its ACL, the request may be rejected. In > addition, a > > user holding the old HIT will find it is very difficult (if > it is possible) to locate A. > > Therefore, I think there should be a third party in the HIP > > architecture to provide the mapping service between the old > HITs and > > the associated new HITs. Currently, I am thinking whether > it is a good > > way to achieve this objective by extending the functionality of > > Rendezvous servers. DNS can also be a candidate. > > > > What do you think about it? Hope to get your comments. > > what about just changing the HI record of the FQDN? Of > course, this does not solve the problem with static ACLs.
- [Hipsec-rg] Hierarchical HITs Xu Xiaohu
- [Hipsec-rg] 答复: Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] Key Revocation Issue Henderson, Thomas R
- [Hipsec-rg] re: 答复: 答复: Key Revocation Issue Xu Xiaohu
- [Hipsec-rg] 答复: 答复: Key Revocation Issue Andrew McGregor
- [Hipsec-rg] 答复: 答复: Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] 答复: Key Revocation Issue Scott Brim
- [Hipsec-rg] 答复: Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] Hierarchical HITs JiangSheng 66104
- [Hipsec-rg] Key Revocation Issue Oleg Ponomarev
- [Hipsec-rg] Hierarchical HITs Oleg Ponomarev
- [Hipsec-rg] 答复: Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] 答复: Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] Key Revocation Issue Miika Komu
- [Hipsec-rg] Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] 答复: Hierarchical HITs Zhang Dacheng
- [Hipsec-rg] 答复: Hierarchical HITs Teemu Koponen
- [Hipsec-rg] Hierarchical HITs JiangSheng 66104
- [Hipsec-rg] Hierarchical HITs Oleg Ponomarev
- [Hipsec-rg] 答复: Hierarchical HITs Zhang Dacheng
- [Hipsec-rg] Hierarchical HITs JiangSheng 66104
- [Hipsec-rg] Hierarchical HITs Julien Laganier
- [Hipsec-rg] Hierarchical HITs Julien Laganier
- [Hipsec-rg] 答复: Hierarchical HITs Julien Laganier
- [Hipsec-rg] Hierarchical HITs Oleg Ponomarev
- [Hipsec-rg] 答复: Hierarchical HITs Sheng Jiang
- [Hipsec-rg] 答复: 答复: Hierarchical HITs Sheng Jiang
- [Hipsec-rg] 答复: Hierarchical HITs Sheng Jiang
- [Hipsec-rg] Hierarchical HITs Oleg Ponomarev
- [Hipsec-rg] Hierarchical HITs (Was: reverse DNS l… JiangSheng 66104
- [Hipsec-rg] Key Revocation Issue Zhang Dacheng
- [Hipsec-rg] Key Revocation Issue Henderson, Thomas R