Re: [IPsec] AD review of draft-ietf-ipsecme-ikev2-intermediate-07

2022-01-13 Thread Valery Smyslov
Hi Ben, > Trimming as appropriate... Further trimming... > > > In a similar vein, it would be good to see some more formal analysis > > > that confirms that this construction authenticates the number of > > > intermediate exchanges that have occurred. I am not sure that I could > > > sketch an

Re: [IPsec] AD review of draft-ietf-ipsecme-ikev2-intermediate-07

2022-01-12 Thread Benjamin Kaduk
Hi Valery, Trimming as appropriate... On Tue, Jan 11, 2022 at 05:55:45PM +0300, Valery Smyslov wrote: > > > Section 3.3.2 > > > >The requirement to support this behavior makes authentication > >challenging: it is not appropriate to add on-the-wire content of the > >IKE_INTERMEDIATE

Re: [IPsec] AD review of draft-ietf-ipsecme-ikev2-intermediate-07

2022-01-12 Thread Benjamin Kaduk
Hi Tero, On Tue, Jan 11, 2022 at 02:22:53PM +0200, Tero Kivinen wrote: > Benjamin Kaduk writes: > > I'd also like to confirm that the current (lack of) Updates: > > relationship between this document and RFC 7296 is correct. In §3.2, we > > reaffirm that the normal IKE rules for assigning

Re: [IPsec] AD review of draft-ietf-ipsecme-ikev2-intermediate-07

2022-01-11 Thread Paul Wouters
On Tue, 11 Jan 2022, Valery Smyslov wrote: This sort of construction invites ambiguity if there is ever some other future exchange that wants to go between IKE_SA_INIT and IKE_AUTH. This seems like a strong argument in support of the approach this draft takes, i.e., make IKE_INTERMEDIATE fully

Re: [IPsec] AD review of draft-ietf-ipsecme-ikev2-intermediate-07

2022-01-11 Thread Valery Smyslov
HI Ben, thank you for your review. > Hi all, > > The core mechanisms here seem in good shape. My main area of > uncertainty relates to how much analysis, and with what degree of > formalism, has been applied to the updated IKE_AUTH procedures that are > supposed to authenticate the

[IPsec] AD review of draft-ietf-ipsecme-ikev2-intermediate-07

2022-01-11 Thread Tero Kivinen
Benjamin Kaduk writes: > I'd also like to confirm that the current (lack of) Updates: > relationship between this document and RFC 7296 is correct. In §3.2, we > reaffirm that the normal IKE rules for assigning Message IDs apply, so > "it is set to 1 for the first IKE_INTERMEDIATE exchange, 2 for

[IPsec] AD review of draft-ietf-ipsecme-ikev2-intermediate-07

2022-01-10 Thread Benjamin Kaduk
Hi all, The core mechanisms here seem in good shape. My main area of uncertainty relates to how much analysis, and with what degree of formalism, has been applied to the updated IKE_AUTH procedures that are supposed to authenticate the intermediate exchange(s). My comments on §3.3.2 have more