[Hipsec-rg] next steps with draft-heer-hip-middle-auth-00

julien.IETF at laposte.net (Julien Laganier) Thu, 24 January 2008 15:58 UTC

From: "julien.IETF at laposte.net"
Date: Thu, 24 Jan 2008 16:58:42 +0100
Subject: [Hipsec-rg] next steps with draft-heer-hip-middle-auth-00
In-Reply-To: <Pine.SOL.4.64.0801241722540.15947@kekkonen.cs.hut.fi>
References: <77F357662F8BFA4CA7074B0410171B6D04049B5D@XCH-NW-5V1.nw.nos.boeing.com> <200801241424.57621.julien.IETF@laposte.net> <Pine.SOL.4.64.0801241722540.15947@kekkonen.cs.hut.fi>
Message-ID: <200801241658.44549.julien.IETF@laposte.net>

On Thursday 24 January 2008, Miika Komu wrote:
> Hi Julien,
>
> may I ask why? If what we want is to public key-based filtering for
> HIP control packets? I think the draft specifies such behaviour and
> avoids replay attacks on HIP control packets as well. (HIT-only-based
> filtering does not tell us whether the HIT is owned by the end-host)

For my own curiosity, what would be the security service provided by HIP 
control packet filtering?

If this is really what you want to do, write it down in the draft. This 
is for sure different that admission/access control, accounting, etc.

--julien