From secmech-bounces@lists.ietf.org Thu Jun 01 17:28:03 2006
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1Flui3-0001I4-Mf; Thu, 01 Jun 2006 17:28:03 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1Flui1-0001HF-K0
	for secmech@ietf.org; Thu, 01 Jun 2006 17:28:01 -0400
Received: from mailfe02.tele2.fr ([212.247.154.44] helo=swip.net)
	by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1Flui0-0005YI-A7
	for secmech@ietf.org; Thu, 01 Jun 2006 17:28:01 -0400
X-T2-Posting-ID: TlrHmwDFCX01iQZd0Fm6v3T8FBlCqve5GwI1mWaefYU=
X-Cloudmark-Score: 0.000000 []
Received: from [80.170.148.89] (HELO DELL.tele2.fr)
	by mailfe02.swip.net (CommuniGate Pro SMTP 5.0.8)
	with ESMTP id 209410886 for secmech@ietf.org;
	Thu, 01 Jun 2006 23:27:58 +0200
Message-Id: <5.2.1.1.0.20060601232742.03866c50@pop.tele2.fr>
X-Sender: eu968071@pop.tele2.fr
X-Mailer: QUALCOMM Windows Eudora Version 5.2.1
Date: Thu, 01 Jun 2006 23:27:59 +0200
To: secmech@ietf.org
From: Pascal Urien <urienp@tele2.fr>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 93238566e09e6e262849b4f805833007
Cc: 
Subject: [SECMECH] Identity Protection in EAP-TLS
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Errors-To: secmech-bounces@lists.ietf.org

Hi Everybody,

A New Internet-Draft is available from the on-line Internet-Drafts directories.


	Title		: Identity Protection within EAP-TLS
	Author(s)	: P. Urien, M. Badra
	Filename	: draft-urien-badra-eap-tls-identity-protection-00.txt
	Pages		: 7
	Date		: 2006-5-31
	
This document defines a mechanism providing EAP-TLS identity
protection.

It defines new TLS extension, in order to negotiate the symmetric
encryption algorithm that is used to encrypt or decrypt the client's
certificate.


A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-urien-badra-eap-tls-identity-protection-00.txt

Pascal 


_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Tue Jun 06 18:45:17 2006
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1FnkIX-0005Ie-JM; Tue, 06 Jun 2006 18:45:17 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1Flvj2-00048g-Sl
	for secmech@ietf.org; Thu, 01 Jun 2006 18:33:08 -0400
Received: from 178.230.13.217.in-addr.dgcsystems.net ([217.13.230.178]
	helo=yxa.extundo.com) by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1Flvj1-00052f-Fj
	for secmech@ietf.org; Thu, 01 Jun 2006 18:33:08 -0400
Received: from localhost.localdomain (yxa.extundo.com [217.13.230.178])
	(authenticated bits=0)
	by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge1) with ESMTP id
	k51MWxpU011867
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Fri, 2 Jun 2006 00:33:00 +0200
From: Simon Josefsson <jas@extundo.com>
To: Pascal Urien <urienp@tele2.fr>
References: <5.2.1.1.0.20060601232742.03866c50@pop.tele2.fr>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:060601:urienp@tele2.fr::lzS6wALLLDN34yr+:2t3/
X-Hashcash: 1:22:060601:secmech@ietf.org::pHHyeJK02BF+Gx9b:ENpi
Date: Fri, 02 Jun 2006 00:32:59 +0200
In-Reply-To: <5.2.1.1.0.20060601232742.03866c50@pop.tele2.fr> (Pascal Urien's
	message of "Thu, 01 Jun 2006 23:27:59 +0200")
Message-ID: <8764jkse04.fsf@latte.josefsson.org>
User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.50 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Status: No, score=-2.4 required=5.0 tests=AWL,BAYES_00,
	FORGED_RCVD_HELO autolearn=ham version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2,
	clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 9182cfff02fae4f1b6e9349e01d62f32
X-Mailman-Approved-At: Tue, 06 Jun 2006 18:45:16 -0400
Cc: secmech@ietf.org
Subject: [SECMECH] Re: Identity Protection in EAP-TLS
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Errors-To: secmech-bounces@lists.ietf.org

Pascal Urien <urienp@tele2.fr> writes:

> Hi Everybody,
>
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>
>
> 	Title		: Identity Protection within EAP-TLS
> 	Author(s)	: P. Urien, M. Badra
> 	Filename	: draft-urien-badra-eap-tls-identity-protection-00.txt
> 	Pages		: 7
> 	Date		: 2006-5-31
> 	
> This document defines a mechanism providing EAP-TLS identity
> protection.
>
> It defines new TLS extension, in order to negotiate the symmetric
> encryption algorithm that is used to encrypt or decrypt the client's
> certificate.

How would your approach compare to using TLS-PSK to set up a TLS
connection, and then within that TLS session, re-handshake with client
certificates?  The client certificates would then be encrypted.

/Simon

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Tue Jun 06 20:01:40 2006
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1FnlUS-0003iQ-9F; Tue, 06 Jun 2006 20:01:40 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1FnlUR-0003iL-7u
	for secmech@ietf.org; Tue, 06 Jun 2006 20:01:39 -0400
Received: from smtp1-g19.free.fr ([212.27.42.27])
	by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1FnlUP-0005F4-W0
	for secmech@ietf.org; Tue, 06 Jun 2006 20:01:39 -0400
Received: from enst.fr (mar92-11-82-245-209-5.fbx.proxad.net [82.245.209.5])
	by smtp1-g19.free.fr (Postfix) with ESMTP id 03BA2911B8;
	Wed,  7 Jun 2006 02:01:36 +0200 (CEST)
Message-ID: <44861757.9070107@enst.fr>
Date: Wed, 07 Jun 2006 02:01:27 +0200
From: Mohamad Badra <badra@enst.fr>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; fr-FR;
	rv:1.0.2) Gecko/20030208 Netscape/7.02
X-Accept-Language: fr-fr, fr
MIME-Version: 1.0
To: Simon Josefsson <jas@extundo.com>
Subject: Re: [SECMECH] Re: Identity Protection in EAP-TLS
References: <5.2.1.1.0.20060601232742.03866c50@pop.tele2.fr>
	<8764jkse04.fsf@latte.josefsson.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 798b2e660f1819ae38035ac1d8d5e3ab
Cc: secmech@ietf.org
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Errors-To: secmech-bounces@lists.ietf.org

Hi Simon,

Simon Josefsson a =E9crit:
> How would your approach compare to using TLS-PSK to set up a TLS
> connection, and then within that TLS session, re-handshake with client
> certificates?  The client certificates would then be encrypted.

The document assumes that there is no PSK shared between the client and=20
the server. Thus, there is no way to encrypt the certificate unless we=20
key derived from the premaster secret (per-session key).

We already published a document (EAP-Double-TLS) which runs like your=20
approch: establishing a TLS shared secret Handshake to set up a=20
protected connection and therefore an Handshake with certificate exchange=
.

> /Simon

Best regards
Badra



_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Thu Jun 29 18:25:18 2006
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1Fw4wo-0005nK-MX; Thu, 29 Jun 2006 18:25:18 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1Fw4wn-0005nA-Se
	for secmech@ietf.org; Thu, 29 Jun 2006 18:25:17 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70]
	helo=sj-iport-1.cisco.com) by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1Fw4wm-0005Ni-Ga
	for secmech@ietf.org; Thu, 29 Jun 2006 18:25:17 -0400
Received: from sj-dkim-3.cisco.com ([171.71.179.195])
	by sj-iport-1.cisco.com with ESMTP; 29 Jun 2006 15:25:16 -0700
Received: from sj-core-2.cisco.com (sj-core-2.cisco.com [171.71.177.254])
	by sj-dkim-3.cisco.com (8.12.11/8.12.11) with ESMTP id k5TMPGGq021135
	for <secmech@ietf.org>; Thu, 29 Jun 2006 15:25:16 -0700
Received: from xbh-sjc-231.amer.cisco.com (xbh-sjc-231.cisco.com
	[128.107.191.100])
	by sj-core-2.cisco.com (8.12.10/8.12.6) with ESMTP id k5TMPDlC019062
	for <secmech@ietf.org>; Thu, 29 Jun 2006 15:25:15 -0700 (PDT)
Received: from xmb-sjc-225.amer.cisco.com ([128.107.191.38]) by
	xbh-sjc-231.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.211);
	Thu, 29 Jun 2006 15:25:13 -0700
X-MimeOLE: Produced By Microsoft Exchange V6.5
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Date: Thu, 29 Jun 2006 15:25:12 -0700
Message-ID: <AC1CFD94F59A264488DC2BEC3E890DE5021047E1@xmb-sjc-225.amer.cisco.com>
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
Thread-Topic: I-D ACTION:draft-salowey-guam-mech-01.txt
Thread-Index: AcabypBRvE8f63I8Sf+UK7p4+9xxggAADrkA
From: "Joseph Salowey \(jsalowey\)" <jsalowey@cisco.com>
To: <secmech@ietf.org>
X-OriginalArrivalTime: 29 Jun 2006 22:25:13.0588 (UTC)
	FILETIME=[E3E6A340:01C69BCA]
DKIM-Signature: a=rsa-sha1; q=dns; l=3083; t=1151619916; x=1152483916;
	c=relaxed/simple; s=sjdkim3001;
	h=Content-Type:From:Subject:Content-Transfer-Encoding:MIME-Version;
	d=cisco.com; i=jsalowey@cisco.com;
	z=From:=22Joseph=20Salowey=20\(jsalowey\)=22=20<jsalowey@cisco.com>
	|Subject:FW=3A=20I-D=20ACTION=3Adraft-salowey-guam-mech-01.txt;
	X=v=3Dcisco.com=3B=20h=3DeHsJqUeZLYbXt7DsTj2WZIqN57E=3D;
	b=v/92yAEIAsVORXCOm7rWDyDknpossti7XNKBZGsITd4GRkcUVPq45ejjDOkIFstZlOIIHia0
	1OgWD5/qFyo546wZZU6Lq1JUCN21ySv3Xvc99b03TG7iYXPO5+BqGoLZ;
Authentication-Results: sj-dkim-3.cisco.com; header.From=jsalowey@cisco.com;
	dkim=pass ( sig from cisco.com verified; ); 
X-Spam-Score: 0.0 (/)
X-Scan-Signature: d185fa790257f526fedfd5d01ed9c976
Cc: 
Subject: [SECMECH] FW: I-D ACTION:draft-salowey-guam-mech-01.txt
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Errors-To: secmech-bounces@lists.ietf.org


> ---------- Forwarded message ----------
> From: Internet-Drafts@ietf.org <Internet-Drafts@ietf.org>
> Date: Jun 28, 2006 12:50 PM
> Subject: I-D ACTION:draft-salowey-guam-mech-01.txt
> To: i-d-announce@ietf.org
>=20
>=20
> A New Internet-Draft is available from the on-line=20
> Internet-Drafts directories.
>=20
>=20
>         Title           : Guidelines for Creating Generally Useful
>                           Authentication Mechanisms (GUAM)
>         Author(s)       : J. Salowey
>         Filename        : draft-salowey-guam-mech-01.txt
>         Pages           : 26
>         Date            : 2006-6-28
>=20
> Generic Security Services API (GSS-API), the Simple Authentication
>    and Security Layer (SASL), and the Extensible=20
> Authentication Protocol
>    (EAP) are three authentication and frameworks used within the IETF
>    that have similar goals.  This document describes guidelines for
>    creating authentication mechanisms that are generally usable in any
>    of these frameworks.
>=20
> A URL for this Internet-Draft is:
> http://www.ietf.org/internet-drafts/draft-salowey-guam-mech-01.txt
>=20
> To remove yourself from the I-D Announcement list, send a=20
> message to i-d-announce-request@ietf.org with the word=20
> unsubscribe in the body of the message.
> You can also visit https://www1.ietf.org/mailman/listinfo/I-D-announce
> to change your subscription settings.
>=20
>=20
> Internet-Drafts are also available by anonymous FTP. Login=20
> with the username "anonymous" and a password of your e-mail=20
> address. After logging in, type "cd internet-drafts" and then
>         "get draft-salowey-guam-mech-01.txt".
>=20
> A list of Internet-Drafts directories can be found in=20
> http://www.ietf.org/shadow.html or=20
> ftp://ftp.ietf.org/ietf/1shadow-sites.txt
>=20
>=20
> Internet-Drafts can also be obtained by e-mail.
>=20
> Send a message to:
>         mailserv@ietf.org.
> In the body type:
>         "FILE /internet-drafts/draft-salowey-guam-mech-01.txt".
>=20
> NOTE:   The mail server at ietf.org can return the document in
>         MIME-encoded form by using the "mpack" utility.  To use this
>         feature, insert the command "ENCODING mime" before the "FILE"
>         command.  To decode the response(s), you will need=20
> "munpack" or
>         a MIME-compliant mail reader.  Different=20
> MIME-compliant mail readers
>         exhibit different behavior, especially when dealing with
>         "multipart" MIME messages (i.e. documents which have=20
> been split
>         up into multiple messages), so check your local=20
> documentation on
>         how to manipulate these messages.
>=20
>=20
> Below is the data which will enable a MIME compliant mail=20
> reader implementation to automatically retrieve the ASCII=20
> version of the Internet-Draft.
>=20
>=20
>=20
>=20
> _______________________________________________
> I-D-Announce mailing list
> I-D-Announce@ietf.org
> https://www1.ietf.org/mailman/listinfo/i-d-announce
>=20

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



