GSAKMP Policy Token Spec
Draft-ietf-msec-tokenspec-sec-00.txt Presented by Hugh Harney
SPARTA, Inc. (410) 872-1515 x203 hh@sparta.com
GSAKMP Policy Token Spec Draft-ietf-msec-tokenspec-sec-00.txt - - PowerPoint PPT Presentation
GSAKMP Policy Token Spec Draft-ietf-msec-tokenspec-sec-00.txt Presented by Hugh Harney SPARTA, Inc. (410) 872-1515 x203 hh@sparta.com Agenda GSAKMP Roles GSAKMP Policy Token Dissemination GSAKMP Token Spec. GSAKMP Roles GO
Draft-ietf-msec-tokenspec-sec-00.txt Presented by Hugh Harney
SPARTA, Inc. (410) 872-1515 x203 hh@sparta.com
– Policy Creation Authority
– Policy enforcer – Policy dissemination
– Policy enforcer
– Policy enforcer
Policy Enforcement Policy Enforcement
– Uniquely identify policy token and group
– Identifies
– Who is allowed into the group
– What are the allowed mechanisms for this group – Pass through policy for crypto application (IPSec)
– Verification of policy token veracity
– Version (Policy Token version) – Protocol ID (GSAKMP or other) – Group ID (Unique identity of cryptographic group)
– Time (Group Owner Time)
– Owner Name PKI
– Rekey Controller Name PKI
– Inclusionary
– Names (X.509 Subject field) NAME (Explicit or Rule) PKI
– Exclusionary
– Name rules NAME (Explicit or Rule) PKI
– Key use (Encryption)
– Group Specific Data (PF Key Data)
– Number of SAs – Secure Associations (SAD/SPD)
– Key Management SA (GSAKMP security suite)
– Rekey Information
– Type – Time
– Unicast SA (Management messages)
– Group Specific Data (PF Key Data)
– Number of SAs – Secure Associations (SAD/SPD)
– Name
– PKI
– Signature Data (Group Owners Signature over Policy Token)