Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: ESP NULL was linux-ipsec: broken for a few days...

From: Rob Glenn <rob.glenn(at)nist.gov>
Date: Fri Aug 07 1998 - 23:23:12 EDT

Niels,

At 02:33 AM 8/8/98 +0200, you wrote:
>This is a poor state of affairs. A single, yet unnamed, vendor

The initial proposal did not ask for mandatory status, that was added later. The reason for this is in Section 5 of the ESP draft. Keep in mind that all of these drafts passed IETF WG last call, and IESG last call. Objections & corrections were noted and made.

>AFAIK NAT has been given as the only 'sensible' reason for 'null esp' so

NAT will not work with ESP_NULL. There was a discussion on this a few months back on the IPsec mailing list. The gist is that part of the IP payload needs to be adjusted in transit and ESP_NULL authenticates the entire payload. This was one of the corrections made shortly after IETF last call.

On the assumption that ESP_Authentication-only is equally as strong as AH, ESP_NULL is a alot easier and hence faster to process. I haven't seen any proposed attacks that would invalidate the assumption.

>I wish it were that easy to make clearly necessary transforms like 3DES
http://www.physnet.uni-hamburg.de/provos/
> Jungiusstrasse 9 E-Mail: provos@wserver.physnet.uni-hamburg.de
Received on Sat Aug 8 00:01:39 1998

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:26 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library