draft-ietf-ntp-using-nts- for-ntp-06
- D. Sibold
NTPWG Interim Meeting, 14th October 2016, Boston
for-ntp-06 D. Sibold NTPWG Interim Meeting, 14th October 2016, - - PowerPoint PPT Presentation
draft-ietf-ntp-using-nts- for-ntp-06 D. Sibold NTPWG Interim Meeting, 14th October 2016, Boston In WG Design Team discussed Items Item Status 1 Mandatory to implemented KE Agreed DTLS - Over separate Port - Piggybacked on NTP header
NTPWG Interim Meeting, 14th October 2016, Boston
Item Status 1 Mandatory to implemented KE Agreed – DTLS
2 Are optional KE mechanism allowed? Open 3 Two-way authentication Agreed
authentication 4 Authorization Agreed
5 Broadcast mode Agreed
However PTP needs broadcast/multicast mode!
2016-10-14
2
Item Status 6 Chicken-egg problem Agreed – Discussed in the section “Security considerations” 7 Unauthenticated time packets Agreed – MUST NOT be applied for time synchronization.
considerations” 8 Cryptographic agility Agreement that cryptographic agility is needed A minimum list of mandatory mechanisms shall be provided Message Authentication Code
performance advantages
embedded devices 9 Cipher suite selection TBD
2016-10-14
3
Item Status 10 Privacy Open
7384)
2016-10-14
4
Item Notes Are optional KE mechanism allowed? Privacy If yes, is the current approach suffient?
2016-10-14
5
Daniel’s draft Abstract Introduction DTLS profile for Network Time Security Transport mechanisms for DTLS records The NTS-encapsulated NTPv4 protocol The NTS Key Establishment protocol NTS Extensions for NTPv4 Recommended format for NTS cookies Security Considerations IANA Considerations
Old draft Abstract Introduction Objectives Terms and Abbreviations Overview of NTS-Secured NTP Protocol Sequence Implementation Notes: ASN.1 Structures and Use
IANA Considerations
Preliminary merged draft Abstract Introduction Objectives Terms and Abbreviations Employing DTLS for NTP Security Protocol Sequence for Time Synchronization Messages in Client-Server Mode IANA Considerations
TBD
2016-10-14
6
Contains also language from the generic draft
response messages
information as application data
2016-10-14
7