Re: Authentication using ESP in Transport Mode

Robert Moskowitz <rgm3@chrysler.com> Tue, 09 July 1996 16:39 UTC

Received: from ietf.cnri.reston.va.us by IETF.CNRI.Reston.VA.US id aa16355; 9 Jul 96 12:39 EDT
Received: from CNRI.Reston.VA.US by IETF.CNRI.Reston.VA.US id aa16351; 9 Jul 96 12:39 EDT
Received: from neptune.tis.com by CNRI.Reston.VA.US id aa14768; 9 Jul 96 12:39 EDT
Received: from neptune.tis.com by neptune.TIS.COM id aa10737; 9 Jul 96 12:18 EDT
Received: from relay.tis.com by neptune.TIS.COM id aa10723; 9 Jul 96 12:13 EDT
Received: by relay.tis.com; id MAA06100; Tue, 9 Jul 1996 12:15:39 -0400
Received: from sol.tis.com(192.33.112.100) by relay.tis.com via smap (V3.1.1) id xma006098; Tue, 9 Jul 96 12:15:17 -0400
Received: from relay.tis.com by tis.com (4.1/SUN-5.64) id AA06849; Tue, 9 Jul 96 12:15:00 EDT
Received: by relay.tis.com; id MAA06093; Tue, 9 Jul 1996 12:15:09 -0400
Received: from copilot.is.chrysler.com(204.189.94.36) by relay.tis.com via smap (V3.1.1) id xma006080; Tue, 9 Jul 96 12:14:45 -0400
Received: by pilotx.firewall.is.chrysler.com; id MAA20654; Tue, 9 Jul 1996 12:17:09 -0400
Received: from mhbclpr2-le0.is.chrysler.com(172.29.128.206) by pilotx.is.chrysler.com via smap (g3.0.1) id sma020643; Tue, 9 Jul 96 12:16:47 -0400
Received: from rgm3 by mhbclpr2-nf0.is.chrysler.com (8.7.5/SMI-4.1) id MAA10496; Tue, 9 Jul 1996 12:10:50 -0400 (EDT)
Message-Id: <2.2.32.19960709160928.00aef9f8@pop3hub.is.chrysler.com>
X-Sender: t3125rm@pop3hub.is.chrysler.com
X-Mailer: Windows Eudora Pro Version 2.2 (32)
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Date: Tue, 09 Jul 1996 12:09:28 -0400
To: Michael Richardson <mcr@milkyway.com>, ipsec@tis.com
Sender: ietf-archive-request@IETF.CNRI.Reston.VA.US
From: Robert Moskowitz <rgm3@chrysler.com>
Subject: Re: Authentication using ESP in Transport Mode
X-Orig-Sender: ipsec-approval@neptune.tis.com
Precedence: bulk

At 03:16 PM 7/5/96 -0400, Michael Richardson wrote:
>In a galaxy far, far away, : Fri, 05 Jul 1996 11:29:03 EST
>>      end-to-end authentication of IP headers.  It is desirable to tweak the
>>      architecture so that authentication provided by ESP has the same
>>      security as authentication provided by AH. Then only a single security
>>      header is needed for end-to-end confidentiality + authentication.
>
>  Except that tunnel mode will most often be used by security gateways, not
>the end-to-end contents.

Not quite.  I THINK it will be used in end-to-gateway-to-end as well.  Yes?

Robert Moskowitz
Chrysler Corporation
(810) 758-8212