Re: [IPsec] I-D Action: draft-ietf-ipsecme-dh-checks-01.txt

Yaron Sheffer <yaronf.ietf@gmail.com> Mon, 01 April 2013 21:29 UTC

Return-Path: <yaronf.ietf@gmail.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D18E221E80A0 for <ipsec@ietfa.amsl.com>; Mon, 1 Apr 2013 14:29:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -99.537
X-Spam-Level:
X-Spam-Status: No, score=-99.537 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FH_HOST_EQ_D_D_D_D=0.765, MISSING_HEADERS=1.292, RCVD_IN_PBL=0.905, RDNS_DYNAMIC=0.1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ctuz2QyVVRf9 for <ipsec@ietfa.amsl.com>; Mon, 1 Apr 2013 14:29:50 -0700 (PDT)
Received: from mail-ea0-x22c.google.com (mail-ea0-x22c.google.com [IPv6:2a00:1450:4013:c01::22c]) by ietfa.amsl.com (Postfix) with ESMTP id 41E9811E80E2 for <ipsec@ietf.org>; Mon, 1 Apr 2013 14:29:50 -0700 (PDT)
Received: by mail-ea0-f172.google.com with SMTP id z7so1181430eaf.17 for <ipsec@ietf.org>; Mon, 01 Apr 2013 14:29:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=x-received:message-id:date:from:user-agent:mime-version:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=Wppg3yHymbllF8wEs0DbdCqgf8RaaQ+iTSJo6NSfwhg=; b=sqpwbwLmq/R/ZBoxcZu1qlxESMUQ4o2kGtKEsYO0fJhgewu3MK3r06RaGBMHiO5iPJ m5KBVs9dnEjl+KcVkDTP8QXeJN3hkXm4Lo+u1tqM4AjhDo35+hDyJImT0i1PTQoSDTsS MvCOjtG5Y2sPHdphr4QawL/Bz9HjTleik7qLYlXgoH3utTzM4Ede14302QkS6KqgjS+A Ey+QWfCtxkoP9muIjU8scblXlzdyS5KYNJbQUAE9JHkCzIoR23qM/rbTP3qPxnAzp5xx 0l5w6y7X/FvCDDec0iSauuLyWTTritO3r6BGFVtZXBq8cCNz28kGq7cmh5tH2Bxf+dhh dTJw==
X-Received: by 10.14.223.69 with SMTP id u45mr2579842eep.23.1364851789366; Mon, 01 Apr 2013 14:29:49 -0700 (PDT)
Received: from [10.0.0.2] (bzq-79-181-109-111.red.bezeqint.net. [79.181.109.111]) by mx.google.com with ESMTPS id d47sm23394138eem.9.2013.04.01.14.29.48 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 01 Apr 2013 14:29:48 -0700 (PDT)
Message-ID: <5159FC4B.2010202@gmail.com>
Date: Tue, 02 Apr 2013 00:29:47 +0300
From: Yaron Sheffer <yaronf.ietf@gmail.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20130308 Thunderbird/17.0.4
MIME-Version: 1.0
CC: ipsec@ietf.org
References: <20130401212242.20227.46655.idtracker@ietfa.amsl.com>
In-Reply-To: <20130401212242.20227.46655.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Subject: Re: [IPsec] I-D Action: draft-ietf-ipsecme-dh-checks-01.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipsec>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Apr 2013 21:29:52 -0000

Hi,

we have submitted a new version of the draft. This version clarifies the 
behavior of IKE peers when the specified tests fail. A subsection of the 
Security Considerations explains the rationale.

Thanks,
	Yaron

On 04/02/2013 12:22 AM, internet-drafts@ietf.org wrote:
>
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>   This draft is a work item of the IP Security Maintenance and Extensions Working Group of the IETF.
>
> 	Title           : Additional Diffie-Hellman Tests for IKEv2
> 	Author(s)       : Yaron Sheffer
>                            Scott Fluhrer
> 	Filename        : draft-ietf-ipsecme-dh-checks-01.txt
> 	Pages           : 8
> 	Date            : 2013-04-01
>
> Abstract:
>     This document adds a small number of mandatory tests required for the
>     secure operation of IKEv2 with elliptic curve groups.  No change is
>     required to IKE implementations that use modular exponential groups,
>     other than a few rarely used so-called DSA groups.  This document
>     updates the IKEv2 protocol, RFC 5996.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-ipsecme-dh-checks
>
> There's also a htmlized version available at:
> http://tools.ietf.org/html/draft-ietf-ipsecme-dh-checks-01
>
> A diff from the previous version is available at:
> http://www.ietf.org/rfcdiff?url2=draft-ietf-ipsecme-dh-checks-01
>
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> IPsec mailing list
> IPsec@ietf.org
> https://www.ietf.org/mailman/listinfo/ipsec
>