Re: [IPsec] New draft on IKE Diffie-Hellman checks

Yaron Sheffer <yaronf.ietf@gmail.com> Mon, 10 December 2012 22:09 UTC

Return-Path: <yaronf.ietf@gmail.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 242B121F8635 for <ipsec@ietfa.amsl.com>; Mon, 10 Dec 2012 14:09:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.475
X-Spam-Level:
X-Spam-Status: No, score=-103.475 tagged_above=-999 required=5 tests=[AWL=0.124, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WIXSAMzn--4N for <ipsec@ietfa.amsl.com>; Mon, 10 Dec 2012 14:09:06 -0800 (PST)
Received: from mail-ee0-f44.google.com (mail-ee0-f44.google.com [74.125.83.44]) by ietfa.amsl.com (Postfix) with ESMTP id 533CB21F8634 for <ipsec@ietf.org>; Mon, 10 Dec 2012 14:09:06 -0800 (PST)
Received: by mail-ee0-f44.google.com with SMTP id b47so2046578eek.31 for <ipsec@ietf.org>; Mon, 10 Dec 2012 14:09:05 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=WV+0Q2Ay96AKrtuQToLB4ZRsN0JYyh3hm87+5qHcrrs=; b=YRccOTdosgzv171mUjekFN54U9G8c2MjtzmOxH+Uz+YLh03VC54042HtPpe//yxs0H xc826ZUe6UG7zd9EN6hY8Dt+47ve4VcazwJkxvQNa09gsHnFXDDzdPFysbS1TVDu+wOu uwzD41decClL58a8OXjX4uLx0LZe+66X12ZWVP421o18Ss3ee5EfnwaJLRqNw/Gy/c0y 0J5T8mLvl191Em5SRcAqf02wj73pieyqWEyVifxecJbz3pzJERso+9rFbwM47SeD5liP 2xVR4nYzmy1yK6qweTu1zWM7nIoWgie5wum/uarWwwFY0hI0aWLtZvc711qKv0rqjnvO eUbw==
Received: by 10.14.223.200 with SMTP id v48mr53928178eep.24.1355177345467; Mon, 10 Dec 2012 14:09:05 -0800 (PST)
Received: from [10.0.0.3] (bzq-79-180-163-165.red.bezeqint.net. [79.180.163.165]) by mx.google.com with ESMTPS id l3sm27808020eem.14.2012.12.10.14.09.03 (version=SSLv3 cipher=OTHER); Mon, 10 Dec 2012 14:09:04 -0800 (PST)
Message-ID: <50C65D7D.6030102@gmail.com>
Date: Tue, 11 Dec 2012 00:09:01 +0200
From: Yaron Sheffer <yaronf.ietf@gmail.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/17.0 Thunderbird/17.0
MIME-Version: 1.0
To: Dan Harkins <dharkins@lounge.org>
References: <50C62D6A.8010709@gmail.com> <d47d708f7a33b4c505b19564b206f12f.squirrel@www.trepanning.net>
In-Reply-To: <d47d708f7a33b4c505b19564b206f12f.squirrel@www.trepanning.net>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Cc: IPsecme WG <ipsec@ietf.org>
Subject: Re: [IPsec] New draft on IKE Diffie-Hellman checks
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipsec>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Dec 2012 22:09:07 -0000

Yes it is. That's why I mentioned that this is my personal opinion. You 
might have different personal opinions.

	Yaron

On 12/11/2012 12:02 AM, Dan Harkins wrote:
>
>    Hello,
>
> On Mon, December 10, 2012 10:43 am, Yaron Sheffer wrote:
>> Hi,
>>
>> following the recent discussion on the mailing list, Scott Fluhrer and
>> myself just published a draft that updates RFC 5996 by adding the
>> required recipient-side tests for ECDH. Please see
>> http://www.ietf.org/internet-drafts/draft-sheffer-ipsecme-dh-checks-00.txt.
>>
>> We have not addressed the issues raised by Dan and Tero regarding
>> inconsistencies between various RFCs that define ECDH groups for IKE. I
>> personally deem these issues to be out of scope of the current document.
>
>    If you're planning on updating a standards-track product of this working
> group then isn't it up to the group to decide whether they want to tackle
> various issues?
>
>    Dan.
>
>