Re: IKEv2 (son-of-ike) draft
Derek Atkins <warlord@mit.edu> Wed, 21 November 2001 17:31 UTC
Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id fALHVJ810048; Wed, 21 Nov 2001 09:31:20 -0800 (PST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id LAA16093 Wed, 21 Nov 2001 11:34:55 -0500 (EST)
To: Henry Spencer <henry@spsystems.net>
Cc: ipsec@lists.tislabs.com
Subject: Re: IKEv2 (son-of-ike) draft
References: <Pine.BSI.3.91.1011121111035.12699K-100000@spsystems.net>
From: Derek Atkins <warlord@mit.edu>
Date: Wed, 21 Nov 2001 11:43:43 -0500
In-Reply-To: Henry Spencer's message of "Wed, 21 Nov 2001 11:12:22 -0500 (EST)"
Message-ID: <sjmwv0kcbwg.fsf@benjamin.ihtfp.org>
Lines: 35
X-Mailer: Gnus v5.7/Emacs 20.7
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk
Henry Spencer <henry@spsystems.net> writes: > > Lack of a standard way of doing it... Do you use raw RSA N/e, PGP key > > format, X.509 format? If a certificate format (PGP/X.509/etc) what > > signatures are required, if any? IKE doesn't specify any of this, and > > quite frankly a number of implementations do it differently. > > So *pick one*. Just because there are ten different ways of doing it > doesn't mean you have to support all ten, or stand there frozen because > you're unable to make up your mind. Right, and implementation A picks method X, and implementation B picks method Y, and implementation C picks method Z, which makes sharing keys a huge hastle. For example, in order to get FreeS/WAN to interoperate with, say, NetBSD, I think I'm going to have to use OpenSSL to general an X.509 self-signed certificate and then extract the key into FreeS/WAN so that NetBSD (and some other implementations) can have access to an X.509 cert. This is just a pain in the butt, and should not be left to implementors. Then again, the Security Area can't seem to agree on a format, either. :( > Henry Spencer > henry@spsystems.net -derek -- Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory Member, MIT Student Information Processing Board (SIPB) URL: http://web.mit.edu/warlord/ PP-ASEL-IA N1NWH warlord@MIT.EDU PGP key available
- IKEv2 (son-of-ike) draft Radia Perlman - Boston Center for Networking
- Re: IKEv2 (son-of-ike) draft Ari Huttunen
- RE: IKEv2 (son-of-ike) draft Sami Vaarala
- Re: IKEv2 (son-of-ike) draft Jan Vilhuber
- Re: IKEv2 (son-of-ike) draft Henry Spencer
- Re: IKEv2 (son-of-ike) draft Ari Huttunen
- Re: IKEv2 (son-of-ike) draft Derek Atkins
- Re: IKEv2 (son-of-ike) draft Henry Spencer
- Re: IKEv2 (son-of-ike) draft Derek Atkins
- Re: IKEv2 (son-of-ike) draft dharkins
- Re: IKEv2 (son-of-ike) draft Henry Spencer
- Re: IKEv2 (son-of-ike) draft Derek Atkins
- Re: IKEv2 (son-of-ike) draft Jan Vilhuber
- RE: IKEv2 (son-of-ike) draft Walker, Jesse