Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-erx-00
Yoav Nir <ynir@checkpoint.com> Thu, 05 May 2011 06:59 UTC
Return-Path: <ynir@checkpoint.com>
X-Original-To: hokey@ietfa.amsl.com
Delivered-To: hokey@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix)
with ESMTP id DA7BFE06EC; Wed, 4 May 2011 23:59:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8.535
X-Spam-Level:
X-Spam-Status: No, score=-8.535 tagged_above=-999 required=5 tests=[AWL=2.064,
BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com
[127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b9+42aWPmQ-m;
Wed, 4 May 2011 23:59:55 -0700 (PDT)
Received: from michael.checkpoint.com (smtp.checkpoint.com [194.29.34.68]) by
ietfa.amsl.com (Postfix) with ESMTP id 6C3B6E0692;
Wed, 4 May 2011 23:59:55 -0700 (PDT)
Received: from il-ex01.ad.checkpoint.com (il-ex01.ad.checkpoint.com
[194.29.34.26]) by michael.checkpoint.com (8.13.8/8.13.8) with ESMTP id
p456xC2G030400; Thu, 5 May 2011 09:59:12 +0300
X-CheckPoint: {4DC257F6-0-1B221DC2-FFFF}
Received: from il-ex03.ad.checkpoint.com (194.29.34.71) by
il-ex01.ad.checkpoint.com (194.29.34.26) with Microsoft SMTP Server (TLS) id
8.2.255.0; Thu, 5 May 2011 09:59:12 +0300
Received: from il-ex01.ad.checkpoint.com ([126.0.0.2]) by
il-ex03.ad.checkpoint.com ([194.29.34.71]) with mapi;
Thu, 5 May 2011 09:59:11 +0300
From: Yoav Nir <ynir@checkpoint.com>
To: Dan Harkins <dharkins@lounge.org>
Date: Thu, 5 May 2011 09:59:08 +0300
Thread-Topic: [IPsec] New I-D: draft-nir-ipsecme-erx-00
Thread-Index: AcwK8e8soLcUNJjRSJCsl/y2/yGw/g==
Message-ID: <FC252A0F-BCF3-458D-B2C1-68CCF64F583F@checkpoint.com>
References: <006FEB08D9C6444AB014105C9AEB133F013ABE025E24@il-ex01.ad.checkpoint.com>
<4DBF19F4.6050804@gmail.com>
<95F1A883-8213-4A57-911B-E660E02A3117@checkpoint.com>
<00a401cc09fd$b152ef00$46298a0a@china.huawei.com>
<8CAC67D8-623B-4738-89B0-4A72C3C7AF95@checkpoint.com>
<b94047babd6474117f7734354425dc0b.squirrel@www.trepanning.net>
<BAE19B87-DE7A-4306-B3F0-D171580BCE57@checkpoint.com>
<86c7cd758de89a6f640f8e55faff11ee.squirrel@www.trepanning.net>
<F27D10DD-0B3A-4BA1-AF42-9D814C761804@checkpoint.com>
<6c5908c5ea31d90ed1a8f96b57bf2d72.squirrel@www.trepanning.net>
In-Reply-To: <6c5908c5ea31d90ed1a8f96b57bf2d72.squirrel@www.trepanning.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "ipsec@ietf.org" <ipsec@ietf.org>, "hokey@ietf.org" <hokey@ietf.org>
Subject: Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-erx-00
X-BeenThere: hokey@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HOKEY WG Mailing List <hokey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/hokey>,
<mailto:hokey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hokey>
List-Post: <mailto:hokey@ietf.org>
List-Help: <mailto:hokey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hokey>,
<mailto:hokey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 05 May 2011 06:59:57 -0000
On May 5, 2011, at 9:17 AM, Dan Harkins wrote: > > Hello, > > On Wed, May 4, 2011 10:45 pm, Yoav Nir wrote: >> >>> >> >> OK. I see what you mean. Certificates are not necessarily better. She >> might have a certificate with a subject like >> "UID=alice,OU=people,O=intranet,DC=example,DC=com", or the AAA server >> might call her "emp715". Either can serve. The VPN gateway needs the >> identity for two thing: >> - For policy lookup. As long as the policy database uses the same name, >> we're fine. >> - For generating logs. There should be a way to map the name in the logs >> to the real person, but I guess this re-conciliation of usernames and >> real names can be done either in generating the logs or in viewing the >> logs. > > Assuming the CA is trustworthy and the peer authenticated with that > certificate then you know that the identity named by the subject name > in the certificate is who that peer is. You can make a definitive > statement about it (although I'm not sure what attributes UID or DC are). > > "emp715" returned in an Access-Accept means nothing because it's > meaningful when used with an EAP method of X inside a realm/domain of Y > and you don't know what either X or Y are. So you can't make any > definitive statement about "emp715". Depending on how large your federation is, "emp715" may be unique. In the simplest setup - one RADIUS server that holds records for all employees, it probably is unique. Otherwise, it should probably be in the form of emp715@example.com. In both cases it should be enough to later map to a real person. If it's not, then the AAA setup has not been done right. > >> Any implementation using EAP has users that are either satisfied with >> "emp715" or use a directory to convert that in the logs to a more >> meaningful names. > > Not to belabor the point, but a user could have an authenticated > identity of "emp715" in one realm/domain (that you don't know) and > a completely different user could have an authenticated identity of > "emp715" in a completely different realm/domain (that you also don't > know). Treating them the same is probably not a wise thing to do from > a policy enforcement standpoint. I think it's up to administrators to make sure that names are unique and traceable. If RADIUS has a record for Alice, with identifier "emp715", and when the VPN gateway looks up this string it gets an entry for Bob, it's a deployment error. Besides, I think we're derailing the conversation. We have to assume that EAP works somehow, otherwise we're not going to do ERP. The question is how to get around the ephemeral identities transmitted in ERP. > > (There's a guy named "Dan Harkins" that owns a chain of theaters in > the state of Arizona in the US. I am not that man and I don't live in > Arizona, but I have received phone calls expressing outrage over the kind > of films that "I" show in "my" family theater, and asking why "I" stopped > giving out free popcorn to patrons on their birthday. I receive these > calls because people take a name, stripped of all context, and assume > something about it. And that is a mistake). Strange. I never get calls from people asking for diaper advice. http://www.yoavnir.com Yoav (not a diaper consultant)
- [HOKEY] New I-D: draft-nir-ipsecme-erx-00 Yoav Nir
- [HOKEY] FW: New I-D: draft-nir-ipsecme-erx-00 Tina Tsou
- [HOKEY] Fw: [IPsec] New I-D: draft-nir-ipsecme-er… Qin Wu
- Re: [HOKEY] Fw: [IPsec] New I-D: draft-nir-ipsecm… Glen Zorn
- Re: [HOKEY] Fw: [IPsec] New I-D: draft-nir-ipsecm… Qin Wu
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Qin Wu
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Yoav Nir
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Qin Wu
- Re: [HOKEY] Fw: [IPsec] New I-D: draft-nir-ipsecm… Glen Zorn
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Yoav Nir
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Dan Harkins
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Yoav Nir
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Dan Harkins
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Yoav Nir
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Yaron Sheffer
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Yoav Nir
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Qin Wu
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Yoav Nir
- Re: [HOKEY] [IPsec] New I-D: draft-nir-ipsecme-er… Qin Wu