Re: [IPsec] I-D Action: draft-ietf-ipsecme-ikev2-multiple-ke-00.txt

"Valery Smyslov" <smyslov.ietf@gmail.com> Fri, 10 January 2020 12:45 UTC

Return-Path: <smyslov.ietf@gmail.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9463212008F for <ipsec@ietfa.amsl.com>; Fri, 10 Jan 2020 04:45:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.498
X-Spam-Level:
X-Spam-Status: No, score=-0.498 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_SORBS_WEB=1.5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id E-kOgT9VsbVN for <ipsec@ietfa.amsl.com>; Fri, 10 Jan 2020 04:45:32 -0800 (PST)
Received: from mail-lf1-x130.google.com (mail-lf1-x130.google.com [IPv6:2a00:1450:4864:20::130]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A44BB12006E for <ipsec@ietf.org>; Fri, 10 Jan 2020 04:45:31 -0800 (PST)
Received: by mail-lf1-x130.google.com with SMTP id n12so1378840lfe.3 for <ipsec@ietf.org>; Fri, 10 Jan 2020 04:45:31 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:references:in-reply-to:subject:date:message-id:mime-version :content-transfer-encoding:thread-index:content-language; bh=cFVAE1XsZkxKZgq0gygT5icHOflJ/ToqNTw+CYw7q6k=; b=V3raOcS622rXh9A/iXQAuDNoMaNoGT5WuAD+guQkvHKs91aY4Zt8XYHKEJuDgssN8I jYO70WVU0qPUY+J0WD37tb2wWtdNW8L6G3XpTaRNbLpj0SWZJwKowbmIOQAsyhnghmDC F5Oc926xDLMeAdb77io7/WYGtqfPgPfy/uxCieObz+0X1F9XkWizQcUNMDW524EWiMr+ Ll0gP3Vm1gF2tJJh4Wzq7J3XVeLhGZ8qbj/ua5lEAxxPKkgh7jemmPndjoIVFkgUuii5 K629zg1eLNTZei9WylYBl4HkmVn0zK2mpPmkyd22cpqxqr6AGu7VhpWdVCzNm3wyZY+J EhEw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:references:in-reply-to:subject:date :message-id:mime-version:content-transfer-encoding:thread-index :content-language; bh=cFVAE1XsZkxKZgq0gygT5icHOflJ/ToqNTw+CYw7q6k=; b=jfmbAKXjXH2yZSUPDE1cv/t+FgzF0xDA2aZg9ypulqwb7Hn64pEQxVWPJYsRWcGh0L cUxI2xEla2WS6Pb8TOL0udCEMUriPR/tJYJjQ6C1OOpZ1PNNdGoqy55kyYDj7S2BY7Ve umRzN/AyhNVSwtOSuPHflPctdCHGhUVdeZlZddmq58NaJx9oxzlMQlZBEnEUBBGT+JPZ 16ZnGco2vTCC3ypnXUhXwBmGnVEhdtBY7+jk+IezGjt7Ht6rFULZnC5TT7MJaZYLnaev OZRdVWuHjUo+Eizk7y0gUlcVXByFwvfu2D/Hlue3R5sf2NVSbEcq6pTEXIXj8wg+I8/I 4Udg==
X-Gm-Message-State: APjAAAU25zsV8qN1q1EFTSNdoFQlIIQPwDk4sRWYQO+NT7UMVgfLyLA0 aVZukrrb0iEJ3s0001V5Nb0F83Sv
X-Google-Smtp-Source: APXvYqyrokkw5ojQ8O4tLaiTMJkz4x9neemvLB3q8/3nUQMzzaaar19Msppn8cP/PBAzBLPLvmDmmw==
X-Received: by 2002:ac2:44ce:: with SMTP id d14mr2307034lfm.140.1578660329652; Fri, 10 Jan 2020 04:45:29 -0800 (PST)
Received: from buildpc ([82.138.51.4]) by smtp.gmail.com with ESMTPSA id n11sm945618ljg.15.2020.01.10.04.45.28 for <ipsec@ietf.org> (version=TLS1 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Fri, 10 Jan 2020 04:45:29 -0800 (PST)
From: Valery Smyslov <smyslov.ietf@gmail.com>
To: ipsec@ietf.org
References: <157865639271.27581.4661383369956651848@ietfa.amsl.com>
In-Reply-To: <157865639271.27581.4661383369956651848@ietfa.amsl.com>
Date: Fri, 10 Jan 2020 15:45:33 +0300
Message-ID: <0a0901d5c7b3$d9ed5220$8dc7f660$@gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQE8lvVuJDEySeKGR6kc3UwpgwNvp6kWNgTA
Content-Language: ru
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/s9o5vVLdTBCoWlZvj0hRZM745uk>
Subject: Re: [IPsec] I-D Action: draft-ietf-ipsecme-ikev2-multiple-ke-00.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 10 Jan 2020 12:45:34 -0000

Hi,

a new version of the draft has been published.

1. The draft name is changed to reflect its adoption by the WG and to better reflect its current concept
2. The concept is shifted from focusing on PQ hybrid mode only to defining a general way of combining
    several key exchanges (whether being classic or PQ) in IKEv2
3. A new dedicated exchange type (IKE_FOLLOWUP_KE) is defined for performing additional key exchanges 
     following CREATE_CHILD_SA exchange (many folks on the list and off the list asked for this)
4. Extra nonces are excluded from additional key exchanges, a pair of nonces
     exchanged in IKE_SA_INIT (or CREATE_CHILD_SA) is used instead (some people complained
     that extra nonces complicated implementations, and it seems that they are not needed for security)
5. IANA considerations text is fixed
6. Some important clarifications and a lot of minor text improvements

Please, review.

Regards,
Valery (for the authors).


> -----Original Message-----
> From: IPsec [mailto:ipsec-bounces@ietf.org] On Behalf Of internet-drafts@ietf.org
> Sent: Friday, January 10, 2020 2:40 PM
> To: i-d-announce@ietf.org
> Cc: ipsec@ietf.org
> Subject: [IPsec] I-D Action: draft-ietf-ipsecme-ikev2-multiple-ke-00.txt
> 
> 
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> This draft is a work item of the IP Security Maintenance and Extensions WG of the IETF.
> 
>         Title           : Multiple Key Exchanges in IKEv2
>         Authors         : C. Tjhai
>                           M. Tomlinson
>                           G. Bartlett
>                           S. Fluhrer
>                           D. Van Geest
>                           O. Garcia-Morchon
>                           Valery Smyslov
> 	Filename        : draft-ietf-ipsecme-ikev2-multiple-ke-00.txt
> 	Pages           : 23
> 	Date            : 2020-01-08
> 
> Abstract:
>    This document describes how to extend the Internet Key Exchange
>    Protocol Version 2 (IKEv2) to allow multiple key exchanges to take
>    place while computing of a shared secret during a Security
>    Association (SA) setup.  The primary application of this feature in
>    IKEv2 is the ability to perform one or more post-quantum key
>    exchanges in conjunction with the classical (Elliptic Curve) Diffie-
>    Hellman key exchange, so that the resulting shared key is resistant
>    against quantum computer attacks.  Another possible application is
>    the ability to combine several key exchanges in situations when no
>    single key exchange algorithm is trusted by both initiator and
>    responder.
> 
>    This document updates RFC7296 by renaming a tranform type 4 from
>    "Diffie-Hellman Group (D-H)" to "Key Exchange Method (KE)" and
>    renaming a field in the Key Exchange Payload from "Diffie-Hellman
>    Group Num" to "Key Exchange Method".  It also renames an IANA
>    registry for this transform type from "Transform Type 4 - Diffie-
>    Hellman Group Transform IDs" to "Transform Type 4 - Key Exchange
>    Method Transform IDs".  These changes generalize key exchange
>    algorithms that can be used in IKEv2.
> 
> 
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-multiple-ke/
> 
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-ipsecme-ikev2-multiple-ke-00
> https://datatracker.ietf.org/doc/html/draft-ietf-ipsecme-ikev2-multiple-ke-00
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
> 
> _______________________________________________
> IPsec mailing list
> IPsec@ietf.org
> https://www.ietf.org/mailman/listinfo/ipsec