Re: is manual keying mandatory
Steve Sneddon <sned@cisco.com> Thu, 19 March 1998 22:03 UTC
Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id RAA21981 for ipsec-outgoing; Thu, 19 Mar 1998 17:03:40 -0500 (EST)
Message-Id: <2.2.32.19980319221600.006f5894@trix.cisco.com>
X-Sender: sned@trix.cisco.com
X-Mailer: Windows Eudora Pro Version 2.2 (32)
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Date: Thu, 19 Mar 1998 14:16:00 -0800
To: ipsec@tis.com
From: Steve Sneddon <sned@cisco.com>
Subject: Re: is manual keying mandatory
Cc: William Dixon <wdixon@microsoft.com>, "Michael C. Richardson" <mcr@sandelman.ottawa.on.ca>
Sender: owner-ipsec@ex.tis.com
Precedence: bulk
Could somebody planning a *commercial* IPSec implementation which actually uses manual keying spend a few minutes and tell us the details of transmittal and storage of keys, etc.? Could they also discuss any "insecurities" inherent in the problem? Or is manual keying in the spec only for diagnostic sorts of images and bakeoffs? TIA At 09:24 AM 3/19/98 -0500, Michael C. Richardson wrote: >-----BEGIN PGP SIGNED MESSAGE----- > > >>>>>> "William" == William Dixon <wdixon@microsoft.com> writes: > > William> Since we have put so much effort into IKE now, I don't think it > William> should be a MUST. > > IKE took a lot of effort because it is complicated. All complicated systems >need good run time diagnostics tools. Manual keying is an important >diagnostic tool because it verifies that the problem isn't in the IPsec >portions. > If supporting a manual keying API requires too much memory, or something, >then alternate boot images may be an option. > > :!mcr!: | Sandelman Software Works Corporation, Ottawa, ON > Michael Richardson |Network and security consulting and contract programming > Personal: <A HREF="http://www.sandelman.ottawa.on.ca/People/Michael_Richardson/Bio.html"> mcr@sandelman.ottawa.on.ca</A>. PGP key available. > Corporate: <A HREF="http://www.sandelman.ottawa.on.ca/SSW/">sales@sandelman.ottawa.on.ca</A>. > > > >-----BEGIN PGP SIGNATURE----- >Version: 2.6.3ia >Charset: latin1 >Comment: Processed by Mailcrypt 3.4, an Emacs/PGP interface > >iQB1AwUBNREqrNiXVu0RiA21AQFl4wMAwLEFCj0YzaRtauWRThZuCe6DSEtbL4xo >ZMSGvd3IRpq9u4E1vk8gcJHoPRYwD4udL8hWsr1X6MSBlf3MoqEnuiUjT83+MYKl >hx0kZZcRGwDBLwKIRlpKEYl1JszOX5m5 >=uGLV >-----END PGP SIGNATURE----- > >
- is manual keying mandatory Roy Pereira
- RE: is manual keying mandatory William Dixon
- Re: is manual keying mandatory Derrell D. Piper
- Re: is manual keying mandatory Bill Sommerfeld
- Re: is manual keying mandatory Dan McDonald
- Re: is manual keying mandatory (fwd) Jackie Wilson
- Re: is manual keying mandatory Bronislav Kavsan
- Re: is manual keying mandatory Perry E. Metzger
- Re: is manual keying mandatory (fwd) Perry E. Metzger
- Re: is manual keying mandatory Michael C. Richardson
- Re: is manual keying mandatory (fwd) Paul Koning
- Re: is manual keying mandatory Phil Servita
- Re: is manual keying mandatory (fwd) Robert Moskowitz
- Re: is manual keying mandatory Robert Moskowitz
- Re: is manual keying mandatory (fwd) Larry Backman
- FW: is manual keying mandatory Roy Pereira
- Re: is manual keying mandatory (fwd) Robert Moskowitz
- RE: is manual keying mandatory (fwd) Rob Adams
- Re: is manual keying mandatory Steve Sneddon
- RE: is manual keying mandatory Bede McCall
- Re: is manual keying mandatory Daniel Harkins
- Re: is manual keying mandatory Bronislav Kavsan
- [Fwd: is manual keying mandatory] Bronislav Kavsan
- Re: is manual keying mandatory Theodore Y. Ts'o
- Re: is manual keying mandatory (fwd) Daniel C. Fox
- Re: is manual keying mandatory (fwd) Paul Lambert
- Re: is manual keying mandatory Steve Sneddon
- Re: is manual keying mandatory Michael Richardson
- Re: is manual keying mandatory Dave Carrel
- Re: is manual keying mandatory Bronislav Kavsan
- Re: is manual keying mandatory Bronislav Kavsan
- Re: is manual keying mandatory Dave Carrel
- RE: is manual keying mandatory Bede McCall
- Re: is manual keying mandatory EKR
- Re: is manual keying mandatory Bronislav Kavsan
- RE: is manual keying mandatory Bede McCall
- Re: is manual keying mandatory Derrell D. Piper
- Re: is manual keying mandatory Perry E. Metzger
- Re: is manual keying mandatory Bronislav Kavsan
- Re: is manual keying mandatory Steve Sneddon
- Re: is manual keying mandatory Ran Atkinson
- Re: is manual keying mandatory (fwd) Hilarie Orman