|
|||||||||||
|
Re[2]: linux-ipsec: broken for a few days...
From: <rob.glenn(at)nist.gov>
Date: Fri Aug 07 1998 - 11:19:17 EDT
"William Allen Simpson" <bsimpson@morningstar.com> wrote:
You missed your calling Bill, you should have been a lawyer. Yes, the idea of a null encryption cipher has been around for quite some time. But, the first point that people decided to treat the idea seriously with regard to IPsec was shortly before the March '98 Raleigh Interop when it appeared in the DOI spec. I believe (no, I don't have any hard evidence to support this) that Steve Kent had been pushing for this for quite some time. I apologize if I mislead anyone on this issue, it was not intentional. >
Given an authenticated SA, no one to date, has specified an attack that would succeed against NULL_ESP + auth_alg and not succeed against AH + auth_alg. If someone knows of such an attack, please bring it forward on the IETF IPsec WG list, or let me know, and I'll bring it up.
> However, it is mandatory to implement _only_ for ISAKMP, and not for
That is NOT a correct interpretation. Re-read Section 5. of the ESP draft. begin-quote A compliant ESP implementation MUST support the following mandatory-to-implement algorithms:
Since ESP encryption and authentication are optional, support for the 2 "NULL" algorithms is required to maintain consistency with the way these services are negotiated. NOTE that while authentication and encryption can each be "NULL", they MUST NOT both be "NULL" end-quote > I recommend that anytime ESP NULL is negotiated, a warning message
Please tell, what evidence is this recommendation based on? > WSimpson@UMich.edu
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:26 EDT |
||||||||||
|
|||||||||||