From mcr@lox.sandelman.ottawa.on.ca  Thu Jan 15 11:45:28 2004
Received: from noxmail.sandelman.ottawa.on.ca (noxmail.sandelman.ottawa.on.ca [205.150.200.166])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA14238
	for <ipseckey-archive@lists.ietf.org>; Thu, 15 Jan 2004 11:45:28 -0500 (EST)
Received: from lox.sandelman.ottawa.on.ca (IDENT:root@lox.sandelman.ottawa.on.ca [205.150.200.178])
	by noxmail.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0FGjMi16882
	for <ipseckey-archive@lists.ietf.org>; Thu, 15 Jan 2004 11:45:22 -0500 (EST)
Received: (from mcr@localhost)
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) id i0FGlIO21981;
	Thu, 15 Jan 2004 11:47:18 -0500 (EST)
Date: Thu, 15 Jan 2004 11:47:18 -0500 (EST)
Message-Id: <200401151647.i0FGlIO21981@lox.sandelman.ottawa.on.ca>
From: mcr@sandelman.ottawa.on.ca
Subject: [ipseckey] Monthly information file for ipseckey@sandelman.ottawa.on.ca
To: ipseckey-archive@ietf.org

WG/mailing list description

IPSEC KEYing information resource record WG (ipseckey)

Please see http://www.ietf.org/html.charters/ipseckey-charter.html
for the official page.

To unsubscribe, email to majordomo@sandelman.ca, body is:
	"unsubscribe ipseckey"



You can always ask majordomo@sandelman.ottawa.on.ca to 
remove you from any list hosted by Sandelman Software 
This message sent to ipseckey-archive@lists.ietf.org


From owner-ipseckey-outgoing@lox.sandelman.ottawa.on.ca  Wed Jan 28 21:30:10 2004
Received: from noxmail.sandelman.ottawa.on.ca (noxmail.sandelman.ottawa.on.ca [205.150.200.166])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA12440
	for <ipseckey-archive@lists.ietf.org>; Wed, 28 Jan 2004 21:30:07 -0500 (EST)
Received: from lox.sandelman.ottawa.on.ca (IDENT:root@lox.sandelman.ottawa.on.ca [205.150.200.178])
	by noxmail.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0T2QqA03900
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified OK);
	Wed, 28 Jan 2004 21:26:54 -0500 (EST)
Received: (from majordom@localhost)
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) id i0T1v9d03320
	for ipseckey-outgoing; Wed, 28 Jan 2004 20:57:09 -0500 (EST)
Received: from noxmail.sandelman.ottawa.on.ca (nox.sandelman.ottawa.on.ca [205.150.200.181])
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0T1v5U03310
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified FAIL)
	for <ipseckey@pophost.sandelman.ottawa.on.ca>; Wed, 28 Jan 2004 20:57:06 -0500 (EST)
Received: from sandelman.ottawa.on.ca (wlan237.sandelman.ca [205.150.200.237] (may be forged))
	by noxmail.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0T1qZM03585
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified OK);
	Wed, 28 Jan 2004 20:52:46 -0500 (EST)
Received: from marajade.sandelman.ottawa.on.ca (marajade [127.0.0.1])
	by sandelman.ottawa.on.ca (8.12.3/8.12.3/Debian-6.6) with ESMTP id i0T1p1qe001005
	(version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=NO);
	Wed, 28 Jan 2004 20:51:10 -0500
Received: from marajade.sandelman.ottawa.on.ca (mcr@localhost)
	by marajade.sandelman.ottawa.on.ca (8.12.3/8.12.3/Debian-6.6) with ESMTP id i0SLUdiC019481;
	Wed, 28 Jan 2004 16:30:39 -0500
To: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
cc: ipseckey@sandelman.ca
Subject: Re: [IPSECKEY] New draft -08- misc 
In-reply-to: Your message of "Tue, 16 Dec 2003 13:46:47 +0100."
             <20031216124647.GH13895@ivan.int-evry.fr> 
Mime-Version: 1.0 (generated by tm-edit 1.8)
Content-Type: text/plain; charset=US-ASCII
Date: Wed, 28 Jan 2004 16:30:39 -0500
Message-ID: <19480.1075325439@marajade.sandelman.ottawa.on.ca>
From: Michael Richardson <mcr@sandelman.ottawa.on.ca>
Sender: owner-ipseckey@sandelman.ottawa.on.ca
Precedence: bulk
X-List: ipseckey@sandelman.ottawa.on.ca

-----BEGIN PGP SIGNED MESSAGE-----


Jean-Jacques, I didn't answer your questions in December because I didn't
realize that they weren't just edit suggestions. I wanted to do the IESG
edits before other suggestions.

>>>>> "JJ" == Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr> writes:
    JJ>   I have, however, a question related to terminology: when we refer to
    JJ> entries in the reverse tree, do we consider these as names (of the form
    JJ> x.y.z.t.in-addr.arpa. or ip6.arpa.) or as addresses when writing about
    JJ> them.  An example would be, should we say:

    JJ>   a) ipseckey RR is associated with a name (regardless of
    JJ>   forward/reverse) 
    JJ>     or
    JJ>   b) ipseckef RR is associated with a name or an address ?

  I think you are asking, 
  
  are "1.2.3.4" and "myhost.example." names, with their presentation format
being:
	4.3.2.1.in-addr.arpa.	and myhost.example.

  or is the "name" 4.3.2.1.in-addr.arpa.

  (This kind of semantic question reminds me of the question:
	Q: "why is the sky blue?"
	A: "'blue' is the name for the colour of the sky")

    JJ>   Para 1.1 and 1.2 are concerned by this terminology decision:
    JJ>   1.1
    JJ>   that is to be associated with a Domain Name System (DNS) name for use
    JJ>   1.2
    >> It is expected that there will often be multiple IPSECKEY resource
    >> records at the same name.
  
    JJ>   I think a) is the correct one, but b) explicitly remind of the
    JJ>   reverse aspect.

  by name, I meant "QNAME" - the presentation format. Not only could there
both an IPSECKEY at QNAME's myhost.example. and 4.3.2.1.in-addr.arpa, but
there could be multiple IPSECKEY at each of QNAME.

    JJ>   I suggest replacing 'what IP address (v4 or v6)' by 'which
    JJ>   system'. Pb is gateway field may be a name and map to several IPs.

  Yes, a good suggestion.

    JJ>   I would like to spawn a quick reflexion about what if the content of
    JJ> the gateway field is an address within the same subnet as the RR
    JJ> owner ?

  Without knowing the subnetting involved, it is hard to say if it is in
the same subnet. Further, given large municipal L2-bridge networks, PPPoE
and 802.11, I would not ascribe any additional trust to something in the same
subnet at all. 

    JJ> what is meant in the record. However, I wonder if we had any discussion
    JJ> about how the RR relates to the identity used in ISAKMP/IKE. I think
    JJ> we do not want to get stuck on this topic in the draft and keep it

  I'm sure that it does relate to the identity used in IKE. However, this
isn't the place to talk about it.

    JJ> default practice should be mentioned. I also realized that adding an
    JJ> identity field in the 
    JJ> RR might have made sense in some 'me tarzan - you jane'
    JJ> scenarii. Comments ?

  It certainly helps if a system has multiple keys (found in the DNS,
returned in random order!) if, when one says "you jane", you can tell it
which key you think it should use to sign.

    JJ>   Lastly, regarding xml2rfc, the following directives may suit some
    JJ>   needs 
    JJ>   :) (available on 1.21 version):

    JJ> <?rfc strict="yes" ?>
    JJ> <?rfc compact="yes" ?>
    JJ> <?rfc subcompact="no" ?>
    JJ> <?rfc toc="yes" ?>
    JJ> <?rfc tocdepth="2" ?>
    JJ> <?rfc sortrefs="yes"?>

  I'll upgrade.

]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [
]   Michael Richardson,    Xelerance Corporation, Ottawa, ON    |net architect[
] mcr@xelerance.com      http://www.sandelman.ottawa.on.ca/mcr/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBQBgp/IqHRg3pndX9AQEn8QQA3ILTqbwvU0kX8aMdMVJRx0yauxfWGLh9
ke0J1CK/BvOEXpp1sfdY1tC240sY9URjuYAp9qvpgaKD+szs/MyV6ZS+Wbszkr5y
4y6IaGT961EwY/U37UIWba6CcbMh84oSQA4EWsEoOZfcfbcvlMiHSUBuQGDrQtQS
v6j+B5RQC2s=
=+LIK
-----END PGP SIGNATURE-----
-
This is the IPSECKEY@sandelman.ca list.
Email to ipseckey-request@sandelman.ca to be removed.


From owner-ipseckey-outgoing@lox.sandelman.ottawa.on.ca  Wed Jan 28 21:31:32 2004
Received: from noxmail.sandelman.ottawa.on.ca (noxmail.sandelman.ottawa.on.ca [205.150.200.166])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA12554
	for <ipseckey-archive@lists.ietf.org>; Wed, 28 Jan 2004 21:31:31 -0500 (EST)
Received: from lox.sandelman.ottawa.on.ca (IDENT:root@lox.sandelman.ottawa.on.ca [205.150.200.178])
	by noxmail.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0T2U2A03923
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified OK);
	Wed, 28 Jan 2004 21:30:05 -0500 (EST)
Received: (from majordom@localhost)
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) id i0T1vBs03325
	for ipseckey-outgoing; Wed, 28 Jan 2004 20:57:11 -0500 (EST)
Received: from noxmail.sandelman.ottawa.on.ca (nox.sandelman.ottawa.on.ca [205.150.200.181])
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0T1v8U03319
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified FAIL)
	for <ipseckey@pophost.sandelman.ottawa.on.ca>; Wed, 28 Jan 2004 20:57:10 -0500 (EST)
Received: from sandelman.ottawa.on.ca (wlan237.sandelman.ca [205.150.200.237] (may be forged))
	by noxmail.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0T1qZO03585
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified OK);
	Wed, 28 Jan 2004 20:52:47 -0500 (EST)
Received: from marajade.sandelman.ottawa.on.ca (marajade [127.0.0.1])
	by sandelman.ottawa.on.ca (8.12.3/8.12.3/Debian-6.6) with ESMTP id i0T1p1qg001005
	(version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=NO);
	Wed, 28 Jan 2004 20:51:11 -0500
Received: from marajade.sandelman.ottawa.on.ca (mcr@localhost)
	by marajade.sandelman.ottawa.on.ca (8.12.3/8.12.3/Debian-6.6) with ESMTP id i0SLc5ok020147;
	Wed, 28 Jan 2004 16:38:05 -0500
To: ipseckey@sandelman.ca
cc: Harald Tveit Alvestrand <harald@alvestrand.no>
Subject: [IPSECKEY] IPSECKEY - man-in-the-middle
In-reply-to: Your message of "Tue, 16 Dec 2003 20:26:51 PST."
             <Pine.NEB.3.96L.1031216201717.26511N-100000@fledge.watson.org> 
Mime-Version: 1.0 (generated by tm-edit 1.8)
Content-Type: text/plain; charset=US-ASCII
Date: Wed, 28 Jan 2004 16:38:04 -0500
Message-ID: <20146.1075325884@marajade.sandelman.ottawa.on.ca>
From: Michael Richardson <mcr@sandelman.ottawa.on.ca>
Sender: owner-ipseckey@sandelman.ottawa.on.ca
Precedence: bulk
X-List: ipseckey@sandelman.ottawa.on.ca

-----BEGIN PGP SIGNED MESSAGE-----


OLD TEXT:

   Note that the danger here only applies to cases where the gateway
   field of the IPSECKEY RR indicates a different entity than the owner
   name of the IPSECKEY RR.  In cases where the end-to-end integrity of
   the IPSECKEY RR is suspect, the end client MUST restrict its use of
   the IPSECKEY RR to cases where the RR owner name matches the content
   of the gateway field.

NEW TEXT:

Note that risk of a man-in-the-middle attack mediated by the IPSECKEY
RR only applies to cases where the gateway field of the IPSECKEY RR
indicates a different entity than the owner name of the IPSECKEY RR.

An active attack on the DNS that caused the wrong IP address to be retrieved
(via forged A RR), and therefore the wrong QNAME to be queried would also
result in a man-in-the-middle attack. This situation exists independantly
of whether or not the IPSECKEY RR is used.

In cases where the end-to-end integrity of
the IPSECKEY RR is suspect, the end client MUST restrict its use
of the IPSECKEY RR to cases where the RR owner name matches the
content of the gateway field.

]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [
]   Michael Richardson,    Xelerance Corporation, Ottawa, ON    |net architect[
] mcr@xelerance.com      http://www.sandelman.ottawa.on.ca/mcr/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBQBgruoqHRg3pndX9AQFg8wP/QsQkaat3kTRQWfJ7d1+SjuVFGy8a6jTL
Q/clQMMuSTJ/R36RcTwMRHcBBbUxIzZbcjVBbg/V9sCNzAYTtZzpORMeAS29m58L
S59SNIXewql8Xtk3HRSnB5y/tdFkqzSOE2b4bcyMDWWdbIiLvFm4arjUuJBeYyM+
nb495RcBLWo=
=e6KQ
-----END PGP SIGNATURE-----
-
This is the IPSECKEY@sandelman.ca list.
Email to ipseckey-request@sandelman.ca to be removed.


From owner-ipseckey-outgoing@lox.sandelman.ottawa.on.ca  Wed Jan 28 21:37:07 2004
Received: from noxmail.sandelman.ottawa.on.ca (noxmail.sandelman.ottawa.on.ca [205.150.200.166])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA13077
	for <ipseckey-archive@lists.ietf.org>; Wed, 28 Jan 2004 21:37:06 -0500 (EST)
Received: from lox.sandelman.ottawa.on.ca (IDENT:root@lox.sandelman.ottawa.on.ca [205.150.200.178])
	by noxmail.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0T2ZeA03971
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified OK);
	Wed, 28 Jan 2004 21:35:43 -0500 (EST)
Received: (from majordom@localhost)
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) id i0T1v2w03292
	for ipseckey-outgoing; Wed, 28 Jan 2004 20:57:02 -0500 (EST)
Received: from noxmail.sandelman.ottawa.on.ca (nox.sandelman.ottawa.on.ca [205.150.200.181])
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0T1uxU03279
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified FAIL)
	for <ipseckey@pophost.sandelman.ottawa.on.ca>; Wed, 28 Jan 2004 20:57:00 -0500 (EST)
Received: from sandelman.ottawa.on.ca (wlan237.sandelman.ca [205.150.200.237] (may be forged))
	by noxmail.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0T1qZC03585
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified OK)
	for <ipseckey@sandelman.ca>; Wed, 28 Jan 2004 20:52:43 -0500 (EST)
Received: from marajade.sandelman.ottawa.on.ca (marajade [127.0.0.1])
	by sandelman.ottawa.on.ca (8.12.3/8.12.3/Debian-6.6) with ESMTP id i0T1p1qi001005
	(version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=NO)
	for <ipseckey@sandelman.ca>; Wed, 28 Jan 2004 20:51:11 -0500
Received: from marajade.sandelman.ottawa.on.ca (mcr@localhost)
	by marajade.sandelman.ottawa.on.ca (8.12.3/8.12.3/Debian-6.6) with ESMTP id i0SLG6oh018152
	for <ipseckey@sandelman.ca>; Wed, 28 Jan 2004 16:16:06 -0500
To: ipseckey@sandelman.ca
Subject: [IPSECKEY] reverse map usage
Mime-Version: 1.0 (generated by tm-edit 1.8)
Content-Type: text/plain; charset=US-ASCII
Date: Wed, 28 Jan 2004 16:16:06 -0500
Message-ID: <18151.1075324566@marajade.sandelman.ottawa.on.ca>
From: Michael Richardson <mcr@sandelman.ottawa.on.ca>
Sender: owner-ipseckey@sandelman.ottawa.on.ca
Precedence: bulk
X-List: ipseckey@sandelman.ottawa.on.ca

-----BEGIN PGP SIGNED MESSAGE-----


Does this text make sense?

===

<section title="Use of reverse (in-addr.arpa) map">
<t>
Often a security gateway will only have access to the IP address to which
communication is desired. It will not know the forward name. As such, it
will frequently be the case that the IP address will be used an index into
the reverse map. 
</t>

<t>
The lookup is done in the usual fashion as for PTR records. The IP address'
octets (IPv4) or nibbles (IPv6) are reversed and looked up under the .arpa.
zone. Any CNAMEs or DNAMEs found SHOULD be followed.
</t>

<t>
Note: even when the IPsec function is the end-host, often only the application 
will know the forward name used. While the case where the application knows
the forward name is common, the user could easily have typed in a literal IP
address. This storage mechanism does not preclude using the forward name
when it is available, but does not require it.
</t>
</section>

]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [
]   Michael Richardson,    Xelerance Corporation, Ottawa, ON    |net architect[
] mcr@xelerance.com      http://www.sandelman.ottawa.on.ca/mcr/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBQBgmkIqHRg3pndX9AQFR1gP+JKPhbebWqApYvK7unp64HBkhnk3saxiw
LEOYFSHY1FUgt3b8CSdzwmt9LuVyBZ4cC5fg+f3jJ2MY2arMAe0GF+22F+Z8XdLH
wjoADALWrXLXwhwBTRhWYdxndc0oMmAP9iWHpYshHJhbCY9P9/28b84xh0PgJPWd
DFSM9PYTs+Y=
=lB3a
-----END PGP SIGNATURE-----
-
This is the IPSECKEY@sandelman.ca list.
Email to ipseckey-request@sandelman.ca to be removed.


From owner-ipseckey-outgoing@lox.sandelman.ottawa.on.ca  Thu Jan 29 05:59:14 2004
Received: from noxmail.sandelman.ottawa.on.ca (noxmail.sandelman.ottawa.on.ca [205.150.200.166])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id FAA12563
	for <ipseckey-archive@lists.ietf.org>; Thu, 29 Jan 2004 05:59:14 -0500 (EST)
Received: from lox.sandelman.ottawa.on.ca (IDENT:root@lox.sandelman.ottawa.on.ca [205.150.200.178])
	by noxmail.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0TAuLA11569
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified OK);
	Thu, 29 Jan 2004 05:56:24 -0500 (EST)
Received: (from majordom@localhost)
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) id i0T9eXT08189
	for ipseckey-outgoing; Thu, 29 Jan 2004 04:40:33 -0500 (EST)
Received: from mail.rfc.se (nic.rfc.se [195.47.254.20])
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0T9eVc08179
	for <ipseckey@sandelman.ca>; Thu, 29 Jan 2004 04:40:32 -0500 (EST)
Received: from criollo.schlyter.se (criollo.schlyter.se [195.47.254.130])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by mail.rfc.se (Postfix) with ESMTP
	id E58871960E; Thu, 29 Jan 2004 10:36:07 +0100 (CET)
Date: Thu, 29 Jan 2004 10:36:07 +0100 (CET)
From: Jakob Schlyter <jakob@rfc.se>
To: Michael Richardson <mcr@sandelman.ottawa.on.ca>
Cc: ipseckey@sandelman.ca
Subject: Re: [IPSECKEY] reverse map usage
In-Reply-To: <18151.1075324566@marajade.sandelman.ottawa.on.ca>
Message-ID: <Pine.OSX.4.58.0401291034210.11285@criollo.schlyter.se>
References: <18151.1075324566@marajade.sandelman.ottawa.on.ca>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: owner-ipseckey@sandelman.ottawa.on.ca
Precedence: bulk
X-List: ipseckey@sandelman.ottawa.on.ca

On Wed, 28 Jan 2004, Michael Richardson wrote:

> <section title="Use of reverse (in-addr.arpa) map">
> <t>
> Often a security gateway will only have access to the IP address to which
> communication is desired. It will not know the forward name. As such, it
> will frequently be the case that the IP address will be used an index into
> the reverse map.
> </t>

what else could be used as an index into the reverse map? if nothing, that
needs rewording I think.


	jakob
-
This is the IPSECKEY@sandelman.ca list.
Email to ipseckey-request@sandelman.ca to be removed.


From owner-ipseckey-outgoing@lox.sandelman.ottawa.on.ca  Thu Jan 29 12:18:35 2004
Received: from noxmail.sandelman.ottawa.on.ca (oetest.freeswan.org [205.150.200.166])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA02358
	for <ipseckey-archive@lists.ietf.org>; Thu, 29 Jan 2004 12:18:34 -0500 (EST)
Received: from lox.sandelman.ottawa.on.ca (IDENT:root@lox.sandelman.ottawa.on.ca [205.150.200.178])
	by noxmail.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0THG8A14626
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified OK);
	Thu, 29 Jan 2004 12:16:11 -0500 (EST)
Received: (from majordom@localhost)
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) id i0THHv827793
	for ipseckey-outgoing; Thu, 29 Jan 2004 12:17:57 -0500 (EST)
Received: from noxmail.sandelman.ottawa.on.ca (nox.sandelman.ottawa.on.ca [205.150.200.181])
	by lox.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0THHtR27786
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified FAIL)
	for <ipseckey@pophost.sandelman.ottawa.on.ca>; Thu, 29 Jan 2004 12:17:56 -0500 (EST)
Received: from sandelman.ottawa.on.ca (marajade.sandelman.ottawa.on.ca [205.150.200.247])
	by noxmail.sandelman.ottawa.on.ca (8.11.6p3/8.11.6) with ESMTP id i0THDPA14613
	(using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified OK);
	Thu, 29 Jan 2004 12:13:30 -0500 (EST)
Received: from marajade.sandelman.ottawa.on.ca (mcr@marajade [127.0.0.1])
	by sandelman.ottawa.on.ca (8.12.3/8.12.3/Debian-6.6) with ESMTP id i0THDP5C003588
	(version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=NO);
	Thu, 29 Jan 2004 12:13:25 -0500
Received: from marajade.sandelman.ottawa.on.ca (mcr@localhost)
	by marajade.sandelman.ottawa.on.ca (8.12.3/8.12.3/Debian-6.6) with ESMTP id i0THDO0N003585;
	Thu, 29 Jan 2004 12:13:24 -0500
To: Jakob Schlyter <jakob@rfc.se>
cc: ipseckey@sandelman.ca
Subject: Re: [IPSECKEY] reverse map usage 
In-reply-to: Your message of "Thu, 29 Jan 2004 10:36:07 +0100."
             <Pine.OSX.4.58.0401291034210.11285@criollo.schlyter.se> 
Mime-Version: 1.0 (generated by tm-edit 1.8)
Content-Type: text/plain; charset=US-ASCII
Date: Thu, 29 Jan 2004 12:13:24 -0500
Message-ID: <3584.1075396404@marajade.sandelman.ottawa.on.ca>
From: Michael Richardson <mcr@sandelman.ottawa.on.ca>
Sender: owner-ipseckey@sandelman.ottawa.on.ca
Precedence: bulk
X-List: ipseckey@sandelman.ottawa.on.ca

-----BEGIN PGP SIGNED MESSAGE-----


>>>>> "Jakob" == Jakob Schlyter <jakob@rfc.se> writes:
    >> Often a security gateway will only have access to the IP address to
    >> which communication is desired. It will not know the forward name. As
    >> such, it will frequently be the case that the IP address will be used
    >> an index into the reverse map.

    Jakob> what else could be used as an index into the reverse map? 

  1) one could use the IP address to find a PTR and the look for the key
     in the forward map. This fails for a number of reasons, but it has been
     suggested. 

  2) one could change the BSD sockets API to take forward names instead of
     struct sockaddr_in, and therefore keep the forward name all the way.
     
  3) HIP does something else, which I won't describe here.

    Jakob> if nothing, that needs rewording I think.

  As for rewording - I'm not sure how else to say it. Can you perhaps
help here?

]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [
]   Michael Richardson,    Xelerance Corporation, Ottawa, ON    |net architect[
] mcr@xelerance.com      http://www.sandelman.ottawa.on.ca/mcr/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [

  

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBQBk/M4qHRg3pndX9AQHkVgP8D3adDSwl2WlrfQMoNzrUu9O0JS7VWuwh
SozD5sW0vslkkdd49bfirBHxvzmDbDtTI9jO550gjVp/q9Uhxzk4YgR1yp40fQZa
FkZIAtKmeohQicpka1rk95UmD9ZiWgglnC9yj90CrUgUBrDUu4o1xGsd2JSlCckw
VoAeHXCNEhM=
=RAM3
-----END PGP SIGNATURE-----
-
This is the IPSECKEY@sandelman.ca list.
Email to ipseckey-request@sandelman.ca to be removed.


