|
|||||||||||
|
[Design] Sam's concerns about 2.00
From: D. Hugh Redelmeier <hugh(at)mimosa.com>
Date: Thu Mar 06 2003 - 13:36:51 EST
1a Packets from the SG to an OE-enabled host will not get through because the SG will try to negotiate a connection but the other side won't be able to find authenticating material for the SG in DNS. 1b Packets from nodes behind the SG will not get out because (i) we've installed a default route to direct all packets from
the SG through ipsec0, and
2. OE-by-default will exacerbate the long-standing problem of clashing security policies. VPN security assumptions are fundamentally different from OE assumptions. We know little about OE connections (they are potentially from strangers). One can decide what nodes one is willing the have a VPN with, and therefore typically much is known. FreeS/WAN as yet has no good (convenient, expressive, effective) way of segregating VPN and OE traffic. This makes VPN and OE on the same host problematic. OE-by-default is not very safe for SGs with VPN connections. 3. OE-by-default, as it is currently implemented, starts up a bunch of machinery, even if it is not going to do anything useful. If there is no published DNS record to provide authenticating material for the SG, OE can never succeed. Yet a new default route is installed, packets are erouted, %pass eroutes are installed, etc.
Hugh Redelmeier
-----BEGIN PGP SIGNATURE-----
iQCVAwUBPmeVR8FAuQPManGZAQFPRwQAlCh1QmsOTkJeJ4U8JUBxaNloz+0vwagS
91Gv3pfUzD7u5PCH14rOc/CVOvv+5gSkVzFkUDnDxd0FnwuMOPoT8RwSn6jgrSK8
6hr51dEMUNTRmFvE3UKyFi+aM67uulnqfTAL73oaaeqTifRac4Eehub+MRH+oJVs
qvvCp1dU4Mo=
Design mailing list Design@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/design Received on Thu Mar 6 15:14:56 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:56 EDT |
||||||||||
|
|||||||||||