Syslog-Sign and Syslog-Auth

1/11/01


Click here to start


Table of Contents

Syslog-Sign and Syslog-Auth

Overview of Presentation

Introduction: Context

Introduction: What We Want From Syslog-Sign

Security Goals

What's Not Possible?

Overview of Syslog-Sign

Messages as Sent

PPT Slide

PPT Slide

PPT Slide

Out-of-Order Messages/Blocks

Messages as Received: A Big Mess

PPT Slide

Missing or Garbled/Altered Messages

Duplicate Messages

Some Terminology

Important Concepts: Signature Group

Important Concepts: Reboot Sessions and Session IDs

Message Index Numbers

Syslog-Sign Messages

Signature Blocks--Structure

Signature Blocks--Fields

Signature Blocks--Fields

Signature Blocks, Cont'd

Signature Blocks, Cont'd

Signature Blocks, Cont'd

Signature Block, Cont'd

Signature Block, Cont'd

Notes: Variable Length Fields

Notes: Redundancy

Missing Signature Blocks

Certificate Blocks

Certificate Blocks, Cont'd

Certificate Blocks, Cont'd

Certificate Blocks, Cont'd

Certificate Blocks, Cont'd

Certificate Blocks, Cont'd

Certificate Blocks, Cont'd

Certificate Blocks, Cont'd

Certificate Blocks, Cont'd

Certificate Blocks, Cont'd

Offline Review

Online Review

Summary: Syslog-Sign Plusses

Syslog-Sign: Minuses

Syslog-Auth | Syslog-Sign

Syslog-Auth and Syslog-Sign

Overview of Syslog-Auth

PPT Slide

PPT Slide

Syslog-Auth: Key Concepts

Authentication Blocks: Format

Auth Block Format

Authentication Block--Components

Authentication Block--Components

Authentication Block--Components

Auth Block Component: Session IDs

Session IDs: Cont'd

Authentication Block--Components

Forwarding Block

How it Works: Device->Collector

How It Works: Forwarded Messages

Forwarded Messages: Status Flags

Forwarded Messages: Cont'd

Why Sticky Flags Matter

More Sticky Flags

Syslog-Auth: Plusses and Minuses

Future of Syslog-Auth

Author: John M Kelsey