Re: [lisp] draft-farinacci-lisp-crypto-01 - Call for WG Adoption

Dino Farinacci <farinacci@gmail.com> Sat, 06 December 2014 00:21 UTC

Return-Path: <farinacci@gmail.com>
X-Original-To: lisp@ietfa.amsl.com
Delivered-To: lisp@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 36CD61A86EC for <lisp@ietfa.amsl.com>; Fri, 5 Dec 2014 16:21:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pVWuWdEYc38E for <lisp@ietfa.amsl.com>; Fri, 5 Dec 2014 16:21:15 -0800 (PST)
Received: from mail-pd0-x22b.google.com (mail-pd0-x22b.google.com [IPv6:2607:f8b0:400e:c02::22b]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8864D1A710D for <lisp@ietf.org>; Fri, 5 Dec 2014 16:21:15 -0800 (PST)
Received: by mail-pd0-f171.google.com with SMTP id y13so1638878pdi.16 for <lisp@ietf.org>; Fri, 05 Dec 2014 16:21:14 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=hVVm4Ei8yp9FH0UlQdGN4YVnQxinMp+AjpFJlsanwQ8=; b=s337LkUT3aIwWcXf7EENlnFtdpkILdL8H0gs8h6VhtRKXFDaoMrxvx0X3vmPXloeHQ cWv8542Z3/rv3yfhzFyDTiQmlB3odGSWS1k6VRmRLg6KIuL+vCU8XUzdKFanJa6G2F0A 1cgq4zFxgy/n8yvVfg7yqvceZR2tYNvOl173IHFk7EC03xybQenKTuz2urPLHfT9NBGZ ZP7y56AlUtIfWH27EOyXDQgo2eFg46t3EmqWA2PODvGIaJXT6jBaddiT8aVEhTdgv0kx a5x/FM/Qki9KFGxSLDPUU+LenX9r1Oeg5xkpG1mK8vJXRpVkVzAAgmzE4eCYTiOVPaQ3 YdrA==
X-Received: by 10.66.139.134 with SMTP id qy6mr32254696pab.128.1417825274863; Fri, 05 Dec 2014 16:21:14 -0800 (PST)
Received: from [10.4.173.178] (mobile-166-171-249-159.mycingular.net. [166.171.249.159]) by mx.google.com with ESMTPSA id gy10sm29893143pbd.67.2014.12.05.16.21.13 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 05 Dec 2014 16:21:13 -0800 (PST)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (1.0)
From: Dino Farinacci <farinacci@gmail.com>
X-Mailer: iPhone Mail (12B436)
In-Reply-To: <5482373A.9060302@cisco.com>
Date: Fri, 05 Dec 2014 16:21:12 -0800
Content-Transfer-Encoding: quoted-printable
Message-Id: <B7B863F1-2948-4D9E-98C3-F11D92B7B40A@gmail.com>
References: <D35D7CD0-20E5-4210-8025-7C92441DD339@gigix.net> <5480B13C.4090203@cisco.com> <97DA0D20-84D3-4478-8F90-C033E67172CD@gmail.com> <5481DCB6.6070300@cisco.com> <B8414A88-F630-4FC3-A2FC-05235D78D483@gmail.com> <54822778.6050505@cisco.com> <54822CE0.7050109@cs.tcd.ie> <5482373A.9060302@cisco.com>
To: Fabio Maino <fmaino@cisco.com>
Archived-At: http://mailarchive.ietf.org/arch/msg/lisp/t_ba9PgnG9459XePYgA9nR77a6k
Cc: "lisp@ietf.org" <lisp@ietf.org>
Subject: Re: [lisp] draft-farinacci-lisp-crypto-01 - Call for WG Adoption
X-BeenThere: lisp@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: List for the discussion of the Locator/ID Separation Protocol <lisp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lisp>, <mailto:lisp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/lisp/>
List-Post: <mailto:lisp@ietf.org>
List-Help: <mailto:lisp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lisp>, <mailto:lisp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 06 Dec 2014 00:21:17 -0000

And since the key material is in an RLOC-record which is covered by LISP-sec authentication, we are covered. 

Dino


> On Dec 5, 2014, at 2:52 PM, Fabio Maino <fmaino@cisco.com> wrote:
> 
>> On 12/5/14, 2:08 PM, Stephen Farrell wrote:
>> 
>>> On 05/12/14 21:45, Fabio Maino wrote:
>>> On 12/5/14, 9:36 AM, Dino Farinacci wrote:
>>>>> Hi Dino,
>>>>> I have no problems with the control plane part. An encap with
>>>>> multiprotocol support would allow to do IPsec encap before LISP
>>>>> encap, and could be used with the unauthenticated DH mechanism that
>>>>> you propose.
>>>> Well draft-farinacci-lisp-crypto-01 with LISP-SEC can give you an
>>>> authenticated DH mechanism as well.
>>> yes, but the DH mechanism itself is unauthenticated.
>> There is no problem in figuring out a way to bind a DH and
>> an authentication exchange. That's been done many times in
>> different protocols.
>> 
>> S.
>> 
> 
> Absolutely, and LISP-SEC is indeed one of the way to do it.
> 
> Fabio