Re: [IPsec] Fw: Preshared key authentication in IKEv2

2009-11-02 Thread Tero Kivinen
Valery Smyslov writes: > Hi Paul and Tero, > > thank you for your answers. > > > > The PRF (or set of PRFs) is known by the receiving party. If the two > > > parties always only use one PRF, it is known. The padding is not a > > > universal solution for the reasons you give, but it works in the >

Re: [IPsec] Fw: Preshared key authentication in IKEv2

2009-11-02 Thread Valery Smyslov
Hi Paul and Tero, thank you for your answers. > > The PRF (or set of PRFs) is known by the receiving party. If the two > > parties always only use one PRF, it is known. The padding is not a > > universal solution for the reasons you give, but it works in the > > common case of peers who know each

Re: [IPsec] Fw: Preshared key authentication in IKEv2

2009-11-02 Thread Tero Kivinen
Paul Hoffman writes: > At 9:58 AM +0300 10/30/09, Valery Smyslov wrote: > >Hi all, > > > >I'd like to reiterate my early message, which I haven't got answer to. > >My concerns are: > > > >1. How padding pre-sahred key with string "Key Pad for IKEv2" > >could help to avoid storing pre-shared key

Re: [IPsec] Fw: Preshared key authentication in IKEv2

2009-10-30 Thread Paul Hoffman
At 9:58 AM +0300 10/30/09, Valery Smyslov wrote: >Hi all, > >I'd like to reiterate my early message, which I haven't got answer to. >My concerns are: > >1. How padding pre-sahred key with string "Key Pad for IKEv2" >could help to avoid storing pre-shared key in IKE implementation >if prf is

[IPsec] Fw: Preshared key authentication in IKEv2

2009-10-29 Thread Valery Smyslov
Hi all, I'd like to reiterate my early message, which I haven't got answer to. My concerns are: 1. How padding pre-sahred key with string "Key Pad for IKEv2" could help to avoid storing pre-shared key in IKE implementation if prf is not known untill IKE_SA_INIT exchange is finished? 2. It