Re: [IPsec] New Version Notification for draft-ietf-ipsecme-qr-ikev2-06.txt
Paul Wouters <paul@nohats.ca> Fri, 18 January 2019 15:22 UTC
Return-Path: <paul@nohats.ca>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 14456130DCB; Fri, 18 Jan 2019 07:22:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nohats.ca
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OPmKFg-Iv2Qw; Fri, 18 Jan 2019 07:22:18 -0800 (PST)
Received: from mx.nohats.ca (mx.nohats.ca [IPv6:2a03:6000:1004:1::68]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0C885128B14; Fri, 18 Jan 2019 07:22:18 -0800 (PST)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 43h4S32HgFzpK; Fri, 18 Jan 2019 16:22:11 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1547824931; bh=gWIINZzMRqvh81enAodS5b+gMokvT0+SsKaNOOMePcg=; h=Date:From:To:cc:Subject:In-Reply-To:References; b=rPfo5SzevfB6xkXLmPDkaEUQce5VnK82M0whQTFcoK9hEf7cMeTrKIpa8E6Ilahx/ vRS/YzQmj3lujPCBWl/ehXfYdPlwjhHILgPWY0Ey3DoCaq7U4qQ/1UIooA2tNRtFxW qVbgeyMmK2mc7hhVXT1mzxMOdRYf9N5gAG//Fvh8=
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id A2joRkrya-aH; Fri, 18 Jan 2019 16:22:09 +0100 (CET)
Received: from bofh.nohats.ca (bofh.nohats.ca [76.10.157.69]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS; Fri, 18 Jan 2019 16:22:08 +0100 (CET)
Received: by bofh.nohats.ca (Postfix, from userid 1000) id C1387379D; Fri, 18 Jan 2019 10:22:07 -0500 (EST)
DKIM-Filter: OpenDKIM Filter v2.11.0 bofh.nohats.ca C1387379D
Received: from localhost (localhost [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id B026C40D358A; Fri, 18 Jan 2019 10:22:07 -0500 (EST)
Date: Fri, 18 Jan 2019 10:22:07 -0500
From: Paul Wouters <paul@nohats.ca>
To: Valery Smyslov <smyslov.ietf@gmail.com>
cc: IPsecME WG <ipsec@ietf.org>, ipsecme-chairs@ietf.org, david.waltermire@nist.gov
In-Reply-To: <012f01d4af22$25cb8230$71628690$@gmail.com>
Message-ID: <alpine.LRH.2.21.1901181011550.826@bofh.nohats.ca>
References: <154781116115.17402.13780278168942489653.idtracker@ietfa.amsl.com> <012f01d4af22$25cb8230$71628690$@gmail.com>
User-Agent: Alpine 2.21 (LRH 202 2017-01-01)
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/zgv5Mz00rA0G7nLQME9dGXimSPU>
Subject: Re: [IPsec] New Version Notification for draft-ietf-ipsecme-qr-ikev2-06.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 Jan 2019 15:22:20 -0000
On Fri, 18 Jan 2019, Valery Smyslov wrote:
> a new version of draft-ietf-ipsecme-qr-ikev2 (-06) has been posted.
> It addresses Paul Wouters' comment about the Security Considerations text.
Thanks!
I have another minor suggested change :)
current:
Note that [RFC6023] allows to
skip creating Child SA in the IKE_AUTH exchange, so that the
supporting peers can rekey the IKE SA before any Child SA is created.
Note also that some information (identities of the peers, feature
negotiation notifications, Vendor IDs etc.) is always exchanged in
initial exchanges and thus cannot be protected from the attack
described above by performing an IKE SA rekey.
new:
It is possible to create a childless IKE SA in IKE_AUTH as specified
in [RFC6023]. This prevents Child SA configuration information from
being transmited in the original IKE SA that is not protected by
a PPK. Information in the initial IKE_INIT and IKE_AUTH exchanges,
such as peer identities, feature notifications and Vendor ID's cannot
be hidden from the attack described above, even if the additional IKE
SA rekey is performed. Although this information would also be available
to a Man-in-the-middle attacker without a quantum computer.
This removes the two "note" from sentences which make them less easy
to read, and quantifies the leaked information a bit in the context of
a simple MITM, non-quantum attack. It explains a bit better why there
isn't a strong reason to try and hide the peer identities and VIDs from
attackers with quantum computers.
Paul
- Re: [IPsec] New Version Notification for draft-ie… Valery Smyslov
- Re: [IPsec] New Version Notification for draft-ie… Paul Wouters
- Re: [IPsec] New Version Notification for draft-ie… Panos Kampanakis (pkampana)
- Re: [IPsec] New Version Notification for draft-ie… Valery Smyslov
- Re: [IPsec] New Version Notification for draft-ie… Paul Wouters
- Re: [IPsec] New Version Notification for draft-ie… Tero Kivinen