|
|||||||||||
|
Re: ESP NULL was linux-ipsec: broken for a few days...
From: Rob Glenn <rob.glenn(at)nist.gov>
Date: Fri Aug 07 1998 - 23:23:12 EDT Niels,
At 02:33 AM 8/8/98 +0200, you wrote:
The initial proposal did not ask for mandatory status, that was added later. The reason for this is in Section 5 of the ESP draft. Keep in mind that all of these drafts passed IETF WG last call, and IESG last call. Objections & corrections were noted and made. >AFAIK NAT has been given as the only 'sensible' reason for 'null esp' so
NAT will not work with ESP_NULL. There was a discussion on this a few months back on the IPsec mailing list. The gist is that part of the IP payload needs to be adjusted in transit and ESP_NULL authenticates the entire payload. This was one of the corrections made shortly after IETF last call. On the assumption that ESP_Authentication-only is equally as strong as AH, ESP_NULL is a alot easier and hence faster to process. I haven't seen any proposed attacks that would invalidate the assumption. >I wish it were that easy to make clearly necessary transforms like 3DES
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:26 EDT |
||||||||||
|
|||||||||||