Re: [IPsec] IPSec, ESP and AH authentication
Stephen Kent <kent@bbn.com> Fri, 19 October 2007 21:25 UTC
Return-path: <ipsec-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1IizLE-0005NE-J4; Fri, 19 Oct 2007 17:25:12 -0400
Received: from ipsec by megatron.ietf.org with local (Exim 4.43) id 1IizLC-0005N8-KY for ipsec-confirm+ok@megatron.ietf.org; Fri, 19 Oct 2007 17:25:10 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1IizLB-0005Ly-Ng for ipsec@ietf.org; Fri, 19 Oct 2007 17:25:09 -0400
Received: from mx11.bbn.com ([128.33.0.80]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IizL5-0003uN-K6 for ipsec@ietf.org; Fri, 19 Oct 2007 17:25:09 -0400
Received: from dhcp89-089-071.bbn.com ([128.89.89.71]) by mx11.bbn.com with esmtp (Exim 4.60) (envelope-from <kent@bbn.com>) id 1IizKq-0006j0-44; Fri, 19 Oct 2007 17:24:48 -0400
Mime-Version: 1.0
Message-Id: <p06240570c33ecf172713@[128.89.89.71]>
In-Reply-To: <13115564.post@talk.nabble.com>
References: <13115564.post@talk.nabble.com>
Date: Fri, 19 Oct 2007 17:17:27 -0400
To: Tjeu <david_gutenberrger@hotmail.com>
From: Stephen Kent <kent@bbn.com>
Subject: Re: [IPsec] IPSec, ESP and AH authentication
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 9182cfff02fae4f1b6e9349e01d62f32
Cc: ipsec@ietf.org
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Errors-To: ipsec-bounces@ietf.org
At 6:26 AM -0700 10/9/07, Tjeu wrote: >Dear All, > >As you might know, IPSec ESP authentication does not authenticate the >destination and source >addresses of the IP header, whereas the IPSec AH authentication does(i.e. >calculatec MAC over them). However, both claim that they offer data origin >authentication. It is not clear for me how the ESP authentication offers >data origin authentication, as the MAC is not computed on the source and >dest addresses. Therefore the attacker could easily modify them. Am I >missing something ? I would be thankful if anyone could provide links where >I could read regarding this subject, in more details. I looked through some >RFC's but they dont seem to help. > > >Thanks, > >Tjeu >-- IPsec ESP does provide data origin authentication. Maybe IPSec doesn't :-). (Note the correct spelling of the architecture.) Steve _______________________________________________ IPsec mailing list IPsec@ietf.org https://www1.ietf.org/mailman/listinfo/ipsec
- Re: [IPsec] IPSec, ESP and AH authentication Steven M. Bellovin
- Re: [IPsec] IPSec, ESP and AH authentication ns srinivasa murthy
- Re: [IPsec] IPSec, ESP and AH authentication Scott G. Kelly
- RE: [IPsec] IPSec, ESP and AH authentication Dunn, Jeffrey, CTR, OASD(HA)/TMA
- RE: [IPsec] IPSec, ESP and AH authentication Scott G. Kelly
- RE: [IPsec] IPSec, ESP and AH authentication Paul Koning
- RE: [IPsec] IPSec, ESP and AH authentication Charlie Kaufman
- RE: [IPsec] IPSec, ESP and AH authentication Dunn, Jeffrey, CTR, OASD(HA)/TMA
- Re: [IPsec] IPSec, ESP and AH authentication Stephen Kent