Revised Pre-Shared and Public Key Sig modes??
Matt Thomas <matt@ljo.dec.com> Fri, 06 March 1998 20:10 UTC
Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id PAA05905 for ipsec-outgoing; Fri, 6 Mar 1998 15:10:20 -0500 (EST)
Message-Id: <199803062023.PAA15057@tecumseh.altavista-software.com>
X-Sender: altapop@ranier.altavista-software.com (Unverified)
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.0
Date: Fri, 06 Mar 1998 15:19:27 -0500
To: ipsec@tis.com
From: Matt Thomas <matt@ljo.dec.com>
Subject: Revised Pre-Shared and Public Key Sig modes??
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Sender: owner-ipsec@ex.tis.com
Precedence: bulk
The Main Mode exchanges for Pre-Shared keys (HASH_x) or Public Key
Signatures (SIG_x) are:
Initiator Responder
HDR, SA -->
<-- HDR, SA
HDR, KE, Ni -->
<-- HDR, KE, Nr
HDR*, IDii, [HASH_I | SIG_I] -->
<-- HDR*, IDir, [HASH_R | SIG_R]
Is there any reason why 1/2 a round trip could be not eliminated by
having Revised versions of these modes such that):
HDR, SA -->
<-- HDR, SA, KE, Nr
HDR, KE, Ni -->
<-- HDR*, IDir, [HASH_R | SIG_R]
HDR*, IDii, [HASH_I | SIG_I] -->
Since the responder has selected a single proposal, he knows what
Diffie-Hellman group is being used so he can generate the correct
Diffie-Hellman payload and it does cut out 1/2 a round trip.
I'll write up a draft add these as new authentication methods
unless someone convinces me this would be a bad idea.
--
Matt Thomas Internet: matt@ljo.dec.com
AltaVista Internet Software WWW URL: <coming eventually>
Digital Equipment Corporation Disclaimer: This message reflects my own
Littleton, MA warped views, etc.