RE: data origin authentication

Goeman Stefan <Stefan.Goeman@siemens.atea.be> Tue, 07 May 2002 17:14 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g47HEmL03446; Tue, 7 May 2002 10:14:48 -0700 (PDT)
Received: by lists.tislabs.com (8.9.1/8.9.1) id MAA10473 Tue, 7 May 2002 12:34:11 -0400 (EDT)
Message-ID: <E76F715C0429D5118F2100508BB9EDEE036FE96C@hrtades7.atea.be>
From: Goeman Stefan <Stefan.Goeman@siemens.atea.be>
To: "'ipsec@lists.tislabs.com'" <ipsec@lists.tislabs.com>
Subject: RE: data origin authentication
Date: Tue, 07 May 2002 18:41:40 +0200
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Type: text/plain; charset="iso-8859-1"
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

Hello All,

(As you all might guess, I am quite new to this stuff).

See my question(s) below

> -----Original Message-----
> From: Henry Spencer [mailto:henry@spsystems.net]
> Sent: dinsdag 7 mei 2002 17:33
> To: Goeman Stefan
> Cc: 'ipsec@lists.tislabs.com'
> Subject: Re: data origin authentication
> 
> 
> On Tue, 7 May 2002, Goeman Stefan wrote:
> > ...I is correct to say
> > that if ESP is used in transport mode, there is no data origin
> > authentication? I would say this because
> > the IP header, containing the source IP address is not 
> authenticated.
> 
> Not really correct.  Yes, the header may be tampered with... but the
> origin of the *data* (the packet contents) is still certain, 
> because only
> someone knowing the authentication key can generate a packet 
> which will
> pass authentication. 
> 
> The header is just the means by which the data is conveyed to the
> destination.  Usually, one cares about authenticating the 
> contents, not
> the header. 
> 
>                                                           
> Henry Spencer
>                                                        
> henry@spsystems.net
> 

If you don't really need to authenticate the header to obtain data origin
authentication, why does AH (rfc 2402) authenticates also the IP header,
and not only the IP payload?

Anyway, thanks for answering all my (stupid?) questions.


Greetings,

Stefan.