[MEXT] AD review of draft-ietf-mext-aaa-ha-goals-01
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[MEXT] AD review of draft-ietf-mext-aaa-ha-goals-01
I have done my AD review on this document.
The document is ready to move forward, but I wanted to note something
regarding requirement G2.12.
This requirement says that it must be possible to support IKEv2 shared
secret authentication. I can see some good and bad ways of implementing
this in terms of the solutions. Is the solution already in some document?
I think we want to pay close attention to how this requirement is
fulfilled and make sure the architecture is right. (Sending keys vs.
specific keys for this HA vs. asking the server to calculate an
authentication value, binding of access keys to things that go across
accesses, mandatory vs. optional confidentiality of transported keys,
etc.) I will ask for early security review on the solutions.
Jari
_______________________________________________
MEXT mailing list
MEXT at ietf.org
https://www.ietf.org/mailman/listinfo/mext
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.