IKEv2 cookie question

Uri Meth <umeth@columbia.sparta.com> Thu, 03 April 2003 23:42 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA20354 for <ipsec-archive@lists.ietf.org>; Thu, 3 Apr 2003 18:42:28 -0500 (EST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id QAA10568 Thu, 3 Apr 2003 16:49:15 -0500 (EST)
Date: Thu, 03 Apr 2003 16:52:48 -0500
From: Uri Meth <umeth@columbia.sparta.com>
To: ipsec@lists.tislabs.com
Subject: IKEv2 cookie question
Message-ID: <20030403165248.A15033@charlie.columbia.sparta.com>
Reply-To: umeth@sparta.com
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
User-Agent: Mutt/1.2.5.1i
Organization: SPARTA Inc. (Secure Systems Engineering Division)
USMail: 9861 Broken Land Parkway, Suite 300, Columbia MD 21046
Phone: (410) 381-9400 x233
Fax: (410) 381-5559
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

In the MSEC group, there has been a proposal to potentially add cookies
to the GSAKMP protocol.  Since IKE had already dealt with this issue I
looked into how you did cookies.  I am very intrigued by your use of
cookies, but in reading through the IKEv2 spec I have some questions.
Either I do not understand your syntax, something is missing, or there
is some mis-information.  Please help me clarify what is happening.

In Section 2.6 - Cookies , you give the disection for you message structure 
using cookies:

       Initiator                          Responder
       -----------                        -----------
       HDR(A,0), SAi1, KEi, Ni   -->

                                 <-- HDR(A,0), N(COOKIE_REQUIRED),
                                                   N(COOKIE)

       HDR(A,0), N(COOKIE), SAi1, KEi, Ni   -->


From this message I interpret that the reponder sends the initiator a
message with two (2) notification payloads, cookie_required and cookie.
The initiator then rebuilds the initial message with the cookie received
from the responder in the notification cookie payload.

However, in Section 3.10.1 - Notify Message Types, you only have a value
for COOKIE and not for COOKIE_REQUIRED.  

All this leads me to believe that what you really meant to say is that
the responder sends a message with one (1) notification payload
containing the Cookie value.  The initiator takes this cookie value from
the notification payload and sends it back to the responder in the
rebuilt initial message.

So which definition is correct?  Is there any way to fix the spec to
clear up this ambiguity?  Thanx

UM
-- 
Uri Meth                            (410) 872 - 1515 x233 (voice)
SPARTA, Inc.                        (410) 872 - 8079      (fax)
7075 Samuel Morse Drive             umeth@sparta.com
Columbia, MD 21046