IKE Phase1 3rd message pair

IKE Phase1 3rd message pair

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
IKE Phase1 3rd message pair pvsnmp 05-22-2006
Posted by on May 22, 2006, 6:01 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,
This is a follow up of the below mentioned discussion.
http://groups.google.com/group/comp.dcom.vpn/browse_thread/thread/b387325cf6d5a302

I would like to know what does the recipient of message 5 of IKE phase
1 do with the ID payload?? Same question applies to the recipient of
message 6.

Thanks and Regards,
Prashant


Pure Networks
Posted by Stephen J. Bevan on May 28, 2006, 7:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
pvsnmp@yahoo.com writes:
> This is a follow up of the below mentioned discussion.
>
http://groups.google.com/group/comp.dcom.vpn/browse_thread/thread/b387325cf6d5a302
>
> I would like to know what does the recipient of message 5 of IKE phase
> 1 do with the ID payload?? Same question applies to the recipient of
> message 6.

I answered that in the last message in the thread you reference.

Posted by on May 29, 2006, 1:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi Stephen,

>However, the IDii does not have to be an IP address. It could be a
>FQDN or an opaque key. Either of these can be used to pass down a
>value that is known only to the initiator and responder. Obviously
>using a FQDN name like "step...@dino.dnsalias.com" would be easy to
>guess but if instead it was a string like "stephen/*WQ732HG" where
>"stephen" is the user-name and "*WQ732HG" is another shared secret
>then this can be used to provide identity protection (stephen) and
>provide a way to use main-mode with a (group) pre-shared key but still
>providing per-user authentication.

In pre-shared key authentication, does the recipient of message 5 or 6
do anything else with the ID than using it for computation of hash?

Thanks and Regards,
Prashant


Posted by Stephen J. Bevan on June 3, 2006, 11:58 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
pvsnmp@yahoo.com writes:
>>However, the IDii does not have to be an IP address. It could be a
>>FQDN or an opaque key. Either of these can be used to pass down a
>>value that is known only to the initiator and responder. Obviously
>>using a FQDN name like "step...@dino.dnsalias.com" would be easy to
>>guess but if instead it was a string like "stephen/*WQ732HG" where
>>"stephen" is the user-name and "*WQ732HG" is another shared secret
>>then this can be used to provide identity protection (stephen) and
>>provide a way to use main-mode with a (group) pre-shared key but still
>>providing per-user authentication.
>
> In pre-shared key authentication, does the recipient of message 5 or 6
> do anything else with the ID than using it for computation of hash?

The recipient should validate the ID according to their security
policy the details of which are not dictated by IKE. So, it can vary
from doing no validation (common if the ID is an IP address) to doing
checks like the ones I describe in the paragraph you quote.

Posted by on June 4, 2006, 12:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> > In pre-shared key authentication, does the recipient of message 5 or 6
> > do anything else with the ID than using it for computation of hash?
>
> The recipient should validate the ID according to their security
> policy the details of which are not dictated by IKE. So, it can vary
> from doing no validation (common if the ID is an IP address) to doing
> checks like the ones I describe in the paragraph you quote.

Thanks Stephen for the reply.

Prashant


Similar ThreadsPosted
IKE Phase1 3 message pair March 24, 2006, 4:28 am
Test message - please ignore September 24, 2005, 4:31 pm
Server message Block January 20, 2006, 1:38 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map