Re: [IPsec] IPSec, ESP and AH authentication

Stephen Kent <kent@bbn.com> Fri, 19 October 2007 21:25 UTC

Return-path: <ipsec-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1IizLE-0005NE-J4; Fri, 19 Oct 2007 17:25:12 -0400
Received: from ipsec by megatron.ietf.org with local (Exim 4.43) id 1IizLC-0005N8-KY for ipsec-confirm+ok@megatron.ietf.org; Fri, 19 Oct 2007 17:25:10 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1IizLB-0005Ly-Ng for ipsec@ietf.org; Fri, 19 Oct 2007 17:25:09 -0400
Received: from mx11.bbn.com ([128.33.0.80]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IizL5-0003uN-K6 for ipsec@ietf.org; Fri, 19 Oct 2007 17:25:09 -0400
Received: from dhcp89-089-071.bbn.com ([128.89.89.71]) by mx11.bbn.com with esmtp (Exim 4.60) (envelope-from <kent@bbn.com>) id 1IizKq-0006j0-44; Fri, 19 Oct 2007 17:24:48 -0400
Mime-Version: 1.0
Message-Id: <p06240570c33ecf172713@[128.89.89.71]>
In-Reply-To: <13115564.post@talk.nabble.com>
References: <13115564.post@talk.nabble.com>
Date: Fri, 19 Oct 2007 17:17:27 -0400
To: Tjeu <david_gutenberrger@hotmail.com>
From: Stephen Kent <kent@bbn.com>
Subject: Re: [IPsec] IPSec, ESP and AH authentication
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 9182cfff02fae4f1b6e9349e01d62f32
Cc: ipsec@ietf.org
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Errors-To: ipsec-bounces@ietf.org

At 6:26 AM -0700 10/9/07, Tjeu wrote:
>Dear All,
>
>As you might know, IPSec ESP authentication does not authenticate the
>destination and source
>addresses of the IP header, whereas the IPSec AH authentication does(i.e.
>calculatec MAC over them). However, both claim that they offer data origin
>authentication. It is not clear for me how the ESP authentication offers
>data origin authentication, as the MAC is not computed on the source and
>dest addresses. Therefore the attacker could easily modify them. Am I
>missing something ? I would be thankful if anyone could provide links where
>I could read regarding this subject, in more details. I looked through some
>RFC's but they dont seem to help.
>
>
>Thanks,
>
>Tjeu
>--

IPsec ESP does provide data origin authentication.  Maybe IPSec doesn't :-).

(Note the correct spelling of the architecture.)

Steve


_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec