IKEv2 with CGA
Jean-Michel Combes
jeanmichel.combes@orange.com
Aurélien Wailly
aurelien.wailly@orange.com
Maryline Laurent
Maryline.Laurent@it-sudparis.eu
2011-10-25 1 ICSNA 2011
IKEv2 with CGA Jean-Michel Combes jeanmichel.combes@orange.com - - PowerPoint PPT Presentation
IKEv2 with CGA Jean-Michel Combes jeanmichel.combes@orange.com Aurlien Wailly aurelien.wailly@orange.com Maryline Laurent Maryline.Laurent@it-sudparis.eu 2011-10-25 ICSNA 2011 1 Outline IPsec IKEv2 CGA IKEv2 with CGA?
jeanmichel.combes@orange.com
aurelien.wailly@orange.com
Maryline.Laurent@it-sudparis.eu
2011-10-25 1 ICSNA 2011
2011-10-25 2 ICSNA 2011
2011-10-25 3 ICSNA 2011
2011-10-25 ICSNA 2011 4
IPsec peer
2011-10-25 ICSNA 2011 5
2011-10-25 6 ICSNA 2011
mandatory
2011-10-25 ICSNA 2011 7
2011-10-25 8 ICSNA 2011
2011-10-25 ICSNA 2011 9
2011-10-25 ICSNA 2011 10
Modifier Subnet Prefix Collision Count Public Key Extension Fields
2011-10-25 ICSNA 2011 11
2011-10-25 12 ICSNA 2011
2011-10-25 ICSNA 2011 13
2011-10-25 ICSNA 2011 14
2011-10-25 ICSNA 2011 15
Name (FQDN) stored in Domain Name Server (DNS)
2011-10-25 ICSNA 2011 16
2011-10-25 17 ICSNA 2011
SAr1)
2011-10-25 ICSNA 2011 18
CERT)
2011-10-25 ICSNA 2011 19
2011-10-25 20 ICSNA 2011
CGA authentication method
2011-10-25 ICSNA 2011 21
the CGA public one
2011-10-25 ICSNA 2011 22
– Step 1: regeneration of the CGA, based on received CGA Parameters – Step 2: validity of data signed with the CGA private key associated to the public one
2011-10-25 ICSNA 2011 23
2011-10-25 24 ICSNA 2011
2011-10-25 ICSNA 2011 25
2011-10-25 ICSNA 2011 26
2011-10-25 ICSNA 2011 27
2011-10-25 28 ICSNA 2011
2011-10-25 29 ICSNA 2011
2011-10-25 ICSNA 2011 30
– Replaced by SHA-3 in CGA IETF RFC
– Allow ECC use
field in DNS ressource records???
2011-10-25 ICSNA 2011 31
2011-10-25 32 ICSNA 2011
2011-10-25 ICSNA 2011 33
2011-10-25 34 ICSNA 2011
2011-10-25 35 ICSNA 2011
[RFC4301]
December 2005. [RFC5996]
Engineering Task Force, September 2010. [RFC3972]
[RFC3971]
Force, March 2005. [CMLN04] Claude Castelluccia, Gabriel Montenegro, Julien Laganier, and Christoph Neumann. Hindering eavesdropping via ipv6
Lecture Notes in Computer Science, pages 309{321. Springer-Verlag, 2004. [LMK07]
draft-laganier-ike-ipv6-cga-02, Internet Engineering Task Force, July 2007. Obsolete. StrongSwan http://www.strongswan.org/ Wireshark http://www.wireshark.org/
2011-10-25 ICSNA 2011 36