[IPsec] New draft on IKE Diffie-Hellman checks

Yaron Sheffer <yaronf.ietf@gmail.com> Mon, 10 December 2012 18:44 UTC

Return-Path: <yaronf.ietf@gmail.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8BDB021F856B for <ipsec@ietfa.amsl.com>; Mon, 10 Dec 2012 10:44:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level:
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5aOZlDlXV5qX for <ipsec@ietfa.amsl.com>; Mon, 10 Dec 2012 10:44:07 -0800 (PST)
Received: from mail-bk0-f44.google.com (mail-bk0-f44.google.com [209.85.214.44]) by ietfa.amsl.com (Postfix) with ESMTP id 1264921F8555 for <ipsec@ietf.org>; Mon, 10 Dec 2012 10:43:58 -0800 (PST)
Received: by mail-bk0-f44.google.com with SMTP id w11so1329963bku.31 for <ipsec@ietf.org>; Mon, 10 Dec 2012 10:43:58 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:subject :content-type:content-transfer-encoding; bh=23ub+X1N4hFSnEJM8ol4rxHdhkfYLM8bLcJvqgb3yuE=; b=u01OOqzg+k1snbca92UNaPfh6fZUw/TgCxdTdTGHeQYADeR0yzgyUfCtgB/+X43RfY DflQhcf8R28d3KZKGApDayeLLST1pyc39uuA04NKkevnkUTMfzVwJm/TGAxaXWw+6t5v Vm2f1rhG1XsJ46DOVWjoc9QshF5ptBdtcWe5Ss+ty2HuCapzezLnRtYX41DsBCjhH4qn 5az6R+jeH8qv9n7laC7imBHskoAti+loxztVqlS4sdUEaOAW00WFSugZ/jI+AMp7DMOQ QyhZjhfId1wJN4HxRVRDP8R1Js9AOSvrnPEktRJ4kIAlJQVxSuQfCsbydNYdTgxTQSHu FC1g==
Received: by 10.204.147.139 with SMTP id l11mr5022066bkv.46.1355165038205; Mon, 10 Dec 2012 10:43:58 -0800 (PST)
Received: from [10.0.0.3] (bzq-79-180-163-165.red.bezeqint.net. [79.180.163.165]) by mx.google.com with ESMTPS id d16sm14979820bkw.2.2012.12.10.10.43.56 (version=SSLv3 cipher=OTHER); Mon, 10 Dec 2012 10:43:57 -0800 (PST)
Message-ID: <50C62D6A.8010709@gmail.com>
Date: Mon, 10 Dec 2012 20:43:54 +0200
From: Yaron Sheffer <yaronf.ietf@gmail.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/17.0 Thunderbird/17.0
MIME-Version: 1.0
To: IPsecme WG <ipsec@ietf.org>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Subject: [IPsec] New draft on IKE Diffie-Hellman checks
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipsec>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Dec 2012 18:44:07 -0000

Hi,

following the recent discussion on the mailing list, Scott Fluhrer and 
myself just published a draft that updates RFC 5996 by adding the 
required recipient-side tests for ECDH. Please see 
http://www.ietf.org/internet-drafts/draft-sheffer-ipsecme-dh-checks-00.txt.

We have not addressed the issues raised by Dan and Tero regarding 
inconsistencies between various RFCs that define ECDH groups for IKE. I 
personally deem these issues to be out of scope of the current document.

Comments are very welcome.

Thanks,
     Yaron