Re: [secdir] secdir review of draft-kuegler-ipsecme-pace-ikev2
Nico Williams <nico@cryptonector.com> Thu, 14 April 2011 18:44 UTC
Return-Path: <nico@cryptonector.com>
X-Original-To: secdir@ietfc.amsl.com
Delivered-To: secdir@ietfc.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfc.amsl.com (Postfix) with ESMTP id F0734E080D for <secdir@ietfc.amsl.com>; Thu, 14 Apr 2011 11:44:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.857
X-Spam-Level:
X-Spam-Status: No, score=-1.857 tagged_above=-999 required=5 tests=[AWL=0.120, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622]
Received: from mail.ietf.org ([208.66.40.236]) by localhost (ietfc.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sOwY8Bm3WXF9 for <secdir@ietfc.amsl.com>; Thu, 14 Apr 2011 11:44:11 -0700 (PDT)
Received: from homiemail-a64.g.dreamhost.com (caiajhbdccah.dreamhost.com [208.97.132.207]) by ietfc.amsl.com (Postfix) with ESMTP id 2C2DAE084C for <secdir@ietf.org>; Thu, 14 Apr 2011 11:44:11 -0700 (PDT)
Received: from homiemail-a64.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a64.g.dreamhost.com (Postfix) with ESMTP id 3825D438080 for <secdir@ietf.org>; Thu, 14 Apr 2011 11:44:10 -0700 (PDT)
DomainKey-Signature: a=rsa-sha1; c=nofws; d=cryptonector.com; h=mime-version :in-reply-to:references:date:message-id:subject:from:to:cc: content-type; q=dns; s=cryptonector.com; b=CUH6V6Vgk3UbrsIVZVK7t 6g4dzHvvvo+WQ7AHGjUFvKVfhxxa96Ckd240r77yDMiUYfUZelcmwx9Mt1O2uloc dIOdvDjmivenfktCRZUyXDB1vUa7yplHkLMU1aB/bovwz1+5rU/BCB8Jfa2sX/WZ hvhsztycOsW9rdFUhnuueU=
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h= mime-version:in-reply-to:references:date:message-id:subject:from :to:cc:content-type; s=cryptonector.com; bh=JsOUtVQp1nPFsYQ/0BEa sDMz/xU=; b=biPyuze9QQZK2WMVeHZNnRp1wDENm5fPozkk3+XnPPfYQ831lOLX xyqJjs3W/47ALctfURCXf4MFMSAGTGcZIMZLLjjk3g/G4KJla2pqvxW3W+V8OL2G xc4VarIFyMbGWKzQK+5MjG1F9fr+Aq54EU/2j7GEODLxWxz4TvMIXmM=
Received: from mail-vx0-f172.google.com (mail-vx0-f172.google.com [209.85.220.172]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by homiemail-a64.g.dreamhost.com (Postfix) with ESMTPSA id 14BAB43807C for <secdir@ietf.org>; Thu, 14 Apr 2011 11:44:10 -0700 (PDT)
Received: by vxg33 with SMTP id 33so1934591vxg.31 for <secdir@ietf.org>; Thu, 14 Apr 2011 11:44:09 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.52.184.8 with SMTP id eq8mr1543471vdc.214.1302806649302; Thu, 14 Apr 2011 11:44:09 -0700 (PDT)
Received: by 10.52.163.228 with HTTP; Thu, 14 Apr 2011 11:44:09 -0700 (PDT)
In-Reply-To: <4DA73C26.5070407@gmail.com>
References: <AC6674AB7BC78549BB231821ABF7A9AEB530189991@EMBX01-WF.jnpr.net> <4DA69C8A.7000305@gmail.com> <BANLkTi=3WCvUgtLdNknDog--UniYM1G9Bg@mail.gmail.com> <4DA72605.10506@gmail.com> <BANLkTikXF=S3NugNBErZZGLngyCECh=jTw@mail.gmail.com> <ced915e87f60e86c5db6f21f7e94d1a3.squirrel@www.trepanning.net> <BANLkTimqGh84igi5iVJop6O2reG8WF8s-Q@mail.gmail.com> <9c05d036d0e99a053cf977d3f2c441db.squirrel@www.trepanning.net> <BANLkTikF_eG3-CfoJi+6fthvt0gg6D=kwQ@mail.gmail.com> <4DA73C26.5070407@gmail.com>
Date: Thu, 14 Apr 2011 13:44:09 -0500
Message-ID: <BANLkTin7tZwKX5zK6Qq2HOtWH17k0omtMA@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Yaron Sheffer <yaronf.ietf@gmail.com>
Content-Type: text/plain; charset="UTF-8"
Cc: "draft-kuegler-ipsecme-pace-ikev2@tools.ietf.org" <draft-kuegler-ipsecme-pace-ikev2@tools.ietf.org>, "secdir@ietf.org" <secdir@ietf.org>
Subject: Re: [secdir] secdir review of draft-kuegler-ipsecme-pace-ikev2
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Apr 2011 18:44:12 -0000
On Thu, Apr 14, 2011 at 1:25 PM, Yaron Sheffer <yaronf.ietf@gmail.com> wrote: > ENONCE in and of itself is not vulnerable to an off-line dictionary attack > because the password encrypts a random bit string, and we take care that > there is no stray entropy (padding, MAC) that such an attacker could use. But the ENONCE paired with the AUTH payloads is subject to off-line dictionary attacks (the attacker will have to have impersonated the responder in order to obtain the necessary material). > As to the bigger question of why the protocol as a whole is not vulnerable > to the attack, you will have to follow the proof in the paper (or maybe just > ask my coauthor). It sounds like you're asserting that PACE is a ZKPP. Is that right? > And regarding the usage scenario: the primary scenario is password-based > machine-to-machine authentication. Yes, sysadmins are human (in most cases > :-) and they tend to use short passwords for machine auth, much more often > than we would have liked. You might want to clarify this in the abstract and introduction then. But even so, as long as the passwords are human memorable and the mechanism is not a ZKPP, then my other comments stand. However, if this is really for machine authentication then I'll be happy with text exhorting admins to pick good passwords. > There is a secondary use case that's the usual human-to-server auth, where > the peers are too lazy to use EAP. I'm questioning whether this scenario is > interesting enough to add a salted "mode" into the protocol. Fair enough.
- [secdir] secdir review of draft-kuegler-ipsecme-p… Stephen Hanna
- Re: [secdir] secdir review of draft-kuegler-ipsec… Yaron Sheffer
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Paul Hoffman
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Yaron Sheffer
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Paul Hoffman
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Dan Harkins
- Re: [secdir] secdir review of draft-kuegler-ipsec… Yaron Sheffer
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Dan Harkins
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Dan Harkins
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Yaron Sheffer
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Yaron Sheffer
- Re: [secdir] secdir review of draft-kuegler-ipsec… Tom Yu
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Nico Williams
- Re: [secdir] secdir review of draft-kuegler-ipsec… Glen Zorn
- Re: [secdir] secdir review of draft-kuegler-ipsec… Dennis Kügler