Re: [Hipsec] Fwd: New Version Notification for draft-ietf-hip-dex-12.txt

2020-02-14 Thread Miika Komu
Hi, ke, 2020-02-12 kello 17:20 +, Jeff Ahrenholz kirjoitti: > > I believe this version answers all the IESG issues. > > > > Please review, there are some important additions. > > > > EKR had a number of security concerns. Some I feel don't apply to > > HIP, like use an AEAD for HIP packet

Re: [Hipsec] Fwd: New Version Notification for draft-ietf-hip-dex-12.txt

2020-02-13 Thread Robert Moskowitz
On 2/12/20 12:20 PM, Jeff Ahrenholz wrote: I believe this version answers all the IESG issues. Please review, there are some important additions. EKR had a number of security concerns. Some I feel don't apply to HIP, like use an AEAD for HIP packet security. But there are a number of

Re: [Hipsec] Fwd: New Version Notification for draft-ietf-hip-dex-12.txt

2020-02-13 Thread Robert Moskowitz
On 2/12/20 11:48 AM, Jeff Ahrenholz wrote: I believe this version answers all the IESG issues. Please review, there are some important additions. EKR had a number of security concerns.  Some I feel don't apply to HIP, like use an AEAD for HIP packet security. But there are a number of

Re: [Hipsec] Fwd: New Version Notification for draft-ietf-hip-dex-12.txt

2020-02-12 Thread Jeff Ahrenholz
>> Looking at Section 6.3 HIP DEX KEYMAT Generation, it discusses >> using Diffie-Hellman derived key Kij, but I don't see anything >> about using I_NONCE. There is a random #I provided by the >> Responder from the PUZZLE parameter, but nothing about a >> random I_NONCE supplied by the Initiator.

Re: [Hipsec] Fwd: New Version Notification for draft-ietf-hip-dex-12.txt

2020-02-12 Thread Robert Moskowitz
On 2/12/20 12:20 PM, Jeff Ahrenholz wrote: I believe this version answers all the IESG issues. Please review, there are some important additions. EKR had a number of security concerns. Some I feel don't apply to HIP, like use an AEAD for HIP packet security. But there are a number of

Re: [Hipsec] Fwd: New Version Notification for draft-ietf-hip-dex-12.txt

2020-02-12 Thread Jeff Ahrenholz
> I believe this version answers all the IESG issues. > > Please review, there are some important additions. > > EKR had a number of security concerns. Some I feel don't apply to HIP, like > use an AEAD for HIP packet security. > > But there are a number of added sections, particularly in

[Hipsec] Fwd: New Version Notification for draft-ietf-hip-dex-12.txt

2020-02-10 Thread Robert Moskowitz
I believe this version answers all the IESG issues. Please review, there are some important additions. EKR had a number of security concerns.  Some I feel don't apply to HIP, like use an AEAD for HIP packet security. But there are a number of added sections, particularly in Security