Manav Bhatia | 2 May 2006 02:38
Picon
Favicon
Gravatar

Re: IS-IS HMAC SHA Cryptographic Authentication

Hi,

We have updated the draft to include HMAC-SHA-384 and HMAC-SHA-512 authentication modes. There were some
other minor comments as well that we had received. Those have been addressed in this version.

http://www.ietf.org/internet-drafts/draft-bhatia-manral-isis-hmac-sha-01.txt

Would appreciate a feedback from the WG.

Cheers,
Manav

----- Original Message ----
From: Vishwas Manral <vishwas <at> ipinfusion.com>
To: isis-wg <at> ietf.org
Sent: Saturday, 22 April, 2006 6:55:51 AM
Subject: RE: [Isis-wg] IS-IS HMAC SHA Cryptographic Authentication

Hi Hannes,

I mostly agree with Tony here, except for a very corner case where we can amplify 
a DoS because we have multiple keys to choose between at the receiver during Key
Rollover.

The point that you bring is an intersting point about KeyRollover. A simple 
way to do it is to also have the Key-Id (opaque value) sent by the sender. The 
sender when doing a key rollover will use a different Key ID(which is shared with
the receiver). As the receiver will have the key with the same Key-ID it can use 
that key for calculating the Hash. We will not have to compute the hash with 
multiple keys which are valid in such a case.
(Continue reading)

Tom Sanders | 3 May 2006 01:56
Picon

Re: IS-IS HMAC SHA Cryptographic Authentication

Hi Manav,

I was wondering if you could explain me how the fact that the LSP
lifetime is set to zero can be exploited by someone even when using
HMAC-SHA authentication algorithms, as proposed in your draft?

You mention that some hash functions require all the fields of the
message text T to be filled with non zero values. If so, then will it
not result in interop issues, where one vendor decides to use non zero
values and the other decides to fill some fields with zeros?

Toms.

P.S.
Overall the draft looks complete and in good shape!

----- Original Message ----
From: Manav Bhatia <manav_bhatia06 <at> yahoo.co.uk>
To: isis-wg <at> ietf.org
Sent: Tuesday, 2 May, 2006 6:08:00 AM
Subject: Re: [Isis-wg] IS-IS HMAC SHA Cryptographic Authentication

Hi,

We have updated the draft to include HMAC-SHA-384 and HMAC-SHA-512
authentication modes. There were some other minor comments as well
that we had received. Those have been addressed in this version.

http://www.ietf.org/internet-drafts/draft-bhatia-manral-isis-hmac-sha-01.txt

(Continue reading)

Manav Bhatia | 3 May 2006 07:17
Picon
Favicon
Gravatar

RE: IS-IS HMAC SHA Cryptographic Authentication

Toms,

] -----Original Message-----
] From: Tom Sanders [mailto:toms.sanders <at> gmail.com] 
] Sent: Wednesday, May 03, 2006 5:26 AM
] To: isis-wg <at> ietf.org
] Subject: Re: [Isis-wg] IS-IS HMAC SHA Cryptographic Authentication
] 
] Hi Manav,
] 
] I was wondering if you could explain me how the fact that the 
] LSP lifetime is set to zero can be exploited by someone even 
] when using HMAC-SHA authentication algorithms, as proposed in 
] your draft?

Since the Remaining Lifetime is set to zero before computing the
authentication, it means that we don't authenticate this particular field.
And this is done so that the LSPs may be aged by routers in between without
requiring them to recompute the authentication data. 

An attacker can set the lifetime to 0 and flood the LSP. The reciever will
not know that this LSP has been tampered with, as the authentication data is
left intact. This LSP will thus be installed by the this router and would
prematurely expire causing all sorts of problem (denial of service). 

] 
] You mention that some hash functions require all the fields 
] of the message text T to be filled with non zero values. If 
] so, then will it not result in interop issues, where one 
] vendor decides to use non zero values and the other decides 
(Continue reading)

Internet-Drafts | 16 May 2006 21:50
Picon
Favicon

I-D ACTION:draft-ietf-isis-ipv6-te-03.txt

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the IS-IS for IP Internets Working Group of the IETF.

	Title		: IPv6 Traffic Engineering in IS-IS
	Author(s)	: J. Harrison, et al.
	Filename	: draft-ietf-isis-ipv6-te-03.txt
	Pages		: 10
	Date		: 2006-5-16
	
This document specifies a method for exchanging IPv6 Traffic
   Engineering information using the IS-IS routing protocol.  The
   described method uses three new TLVs, together with two new sub-TLVs
   of the Extended IS Reachability TLV.  The information distributed
   allows a CSPF algorithm to calculate traffic engineered routes using
   IPv6 addresses.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-isis-ipv6-te-03.txt

To remove yourself from the I-D Announcement list, send a message to 
i-d-announce-request <at> ietf.org with the word unsubscribe in the body of the message.  
You can also visit https://www1.ietf.org/mailman/listinfo/I-D-announce 
to change your subscription settings.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-isis-ipv6-te-03.txt".

A list of Internet-Drafts directories can be found in
(Continue reading)


Gmane