RE: data origin authentication
Christina Helbig <cbh@zyfer.com> Wed, 08 May 2002 19:33 UTC
Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g48JXbL05562; Wed, 8 May 2002 12:33:37 -0700 (PDT)
Received: by lists.tislabs.com (8.9.1/8.9.1) id LAA14875 Wed, 8 May 2002 11:46:23 -0400 (EDT)
Message-ID: <6F0AA176DA68704884B7507AE6907E180817DD@snake012.odetics.com>
From: Christina Helbig <cbh@zyfer.com>
To: 'Goeman Stefan' <Stefan.Goeman@siemens.atea.be>
Cc: "'ipsec@lists.tislabs.com'" <ipsec@lists.tislabs.com>
Subject: RE: data origin authentication
Date: Wed, 08 May 2002 08:57:50 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Type: text/plain; charset="iso-8859-1"
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk
Hi, Stefan I haven't claim that ESP offers non-repudiation. ESP offers data origin authentication without non-repudiation. This was only a remark about a possible misunderstanding of the term "data origin authentication" in the sense that there is only one possible origin. Greetings Christina > -----Original Message----- > From: Goeman Stefan [mailto:Stefan.Goeman@siemens.atea.be] > Sent: Wednesday, May 08, 2002 1:12 AM > To: 'ipsec@lists.tislabs.com' > Subject: RE: data origin authentication > > > Hello All, > > > -----Original Message----- > > From: Christina Helbig [mailto:cbh@zyfer.com] > > Sent: dinsdag 7 mei 2002 21:02 > > To: 'Joern Sierwald'; ipsec@lists.tislabs.com > > Subject: RE: data origin authentication > > > > > > Hello, Joern > > if you are a bad guy and you own a in-bound SA you can > > produced a faked ESP > > packet that looks like its come from the other party of your > > in-bound SA. > > Then you can claim that you got this packet from the other > > party. So the > > data origin authentication of ESP (two parties know the same > > authentication > > key) don't deliver non-repudiation of data origin. But a > > receiver can be > > sure that the sender of an incoming ESP packet is only the > > other party of > > the related in-bound SA or the receiver itself. > > Non-repudiation. > Hmm. > Checking the rfc's, it is nowhere claimed that ESP and/or AH > offers non-repudiation as a security service. > > (But perhaps non-repudiation is a must and then solutions have > to be developed.) > > > Greetings, > > Stefan. >
- data origin authentication Goeman Stefan
- Re: data origin authentication Henry Spencer
- Re: data origin authentication Joern Sierwald
- Re: data origin authentication Bill Sommerfeld
- RE: data origin authentication Goeman Stefan
- Re: data origin authentication Michael Richardson
- Re: data origin authentication Michael Richardson
- RE: data origin authentication Henry Spencer
- RE: data origin authentication Christina Helbig
- RE: data origin authentication Goeman Stefan
- RE: data origin authentication Joern Sierwald
- RE: data origin authentication Christina Helbig