SEND WG IETF 57, Vienna Monday, July 14, 9:00 am.

Slides:



Advertisements
Similar presentations
NSIS WG 71th IETF Philadelphia, PA, USA March 12, 2008 WG chairs:John Loughney Martin Stiemerling.
Advertisements

HIP WG Stockholm, Sweden THURSDAY, July 30, 2009, Congresshall C.
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
Detecting Network Attachment IETF61 Chairs: Pekka Nikander, Greg Daley.
PPSP Working Group IETF-89 London, UK 16:10-18:40, Tuesday, Webex: participation.html.
SIP working group status Keith Drage, Dean Willis.
Seamoby – IETF 56 Pat Calhoun Airespace James Kempf DoCoMo Labs USA.
NETLMM Meeting IETF 67 James Kempf Phil Roberts
Dime WG Status Update IETF#81, THURSDAY, July 28, Afternoon Session I.
1 DHCP Authentication Discussion INTAREA meeting, 70th IETF Vancouver, Canada Jari Arkko and Ralph Droms.
July 2011IETF TRILL WG1 TRILL Working Group TRansparent Interconnection of Lots of Links Mailing list: Tools site:
The HIP-HOP proposal draft-matthews-p2psip-hip-hop-00 Philip Matthews
HIP Working Group IETF 62 Gonzalo Camarillo David Ward.
November 2010IETF TRILL WG1 TRILL Working Group TRansparent Interconnection of Lots of Links Mailing list: Tools site:
Multi6 Working Group IETF-61, Washington D.C November 8-12, 2004.
1 Virtual Router Redundancy Protocol (VRRP) San Francisco IETF VRRP Working Group March 2003 San Francisco IETF Mukesh Gupta / Nokia Chair.
1 Arkko, 57th IETF: SEND base protocol issue list Issues in the SEND base document draft-ietf-send-ipsec-01.txt
Multiple Interfaces (MIF) WG IETF 79, Beijing, China Margaret Wasserman Hui Deng
IPv6 Working Group IETF58 Minneapolis November 2003 Bob Hinden & Brian Haberman Chairs.
Peer to Peer Streaming Protocol (PPSP) BOF Gonzalo Camarillo Ericsson Yunfei Zhang China Mobile IETF76, Hiroshima, Japan 13:00~15:00 THURSDAY, Nov 12,
Bridge WG Status Report David Harrington Dan Romascanu This presentation will probably involve audience discussion, which will create action items. Use.
IPv6 WORKING GROUP (IPNGWG) December 2000 San Diego IETF Bob Hinden / Nokia Steve Deering / Cisco Systems Co-Chairs.
Mobile IPv6 with IKEv2 and revised IPsec architecture IETF 61
Slide title In CAPITALS 50 pt Slide subtitle 32 pt DNA wg IETF71.
BFD IETF 83. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any.
1 MIP6-IETF63 Mobility for IPv6 [MIP6] Tuesday, August 2, Afternoon Session II & Afternoon Session III IETF63 Chair(s): Basavaraj.
63rd IETF Paris August 2005 CCAMP Working Group Online Agenda and Slides at:
IPR WG IETF 62 Minneapolis. IPR WG: Administrivia Blue sheets Scribes Use the microphones Note Well.
Benchmarking Methodology WG (bmwg) 57th IETF – Vienna, Austria Tuesday, July 15, 2003, and Chairs: –Kevin Dubray
IETF-53-IPv6 WG- Cellular host draft 1 Minimum IPv6 Functionality for a Cellular Host Jari Arkko Peter Hedman Gerben Kuijpers Hesham Soliman John Loughney.
1 cellhost-ipv6-52.ppt/ December 13, 2001 / John A. Loughney Minimum IPv6 Functionality for a Cellular Host John Loughney, Pertti Suomela, Juha Wiljakka,
IETF #85 - NETCONF WG session 1 NETCONF WG IETF 85, Atlanta, USA WEDNESDAY, November 7, Bert Wijnen Mehmet Ersue.
David B. Johnson Rice University Department of Computer Science DSR Draft Status Monarch Project 57th IETF.
NETWORK-BASED MOBILITY EXTENSIONS WG (NETEXT) July 28 th, 2011 IETF81 1.
56 th IETF Internet Fax WG Claudio Allocchio Hiroshi Tamura Mar 18 th 2003.
1 Internet Area Open Meeting 67th IETF San Diego, CA Jari Arkko and Mark Townsley Mailing list:
Fri 24 Jul 2015SIDR IETF 93 Prague, CZ1 SIDR Working Group IETF 93 Prague, CZ Friday, 24 Jul 2015.
IPng WORKING GROUP November 1999 Washington DC IETF Bob Hinden / Nokia Steve Deering / Cisco Systems Co-Chairs.
Network Layer Security Howie Weiss (NASA/JPL/Cobham Analytic Solutions) Mike Pajevski (NASA/JPL) May 2010.
IP Flow Information eXport (IPFIX)
Network Slicing (netslicing) BoF
Agenda Alexey, Yoav, Tobias July 2012
Encryption and Network Security
Chairs: Samita Chakrabarti, Gabriel Montenegro
SIPPING Working Group IETF 69
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
IPSEC - IETF 55 Agenda Agenda Bashing (5 min) I-D Status (5 min)
In-Band Authentication Extension for Protocol Independent Multicast (PIM) draft-bhatia-zhang-pim-auth-extension-00 Manav Bhatia
IKEv2 Mobility and Multihoming WG
Service Function Chaining (SFC)
TRILL Working Group TRansparent Interconnection of Lots of Links
TRILL Working Group TRansparent Interconnection of Lots of Links
IETF57 Vienna July 2003 Bob Hinden & Margaret Wasserman Chairs
Extensible Messaging and Presence Protocol (XMPP) WG
IETF-70 EAP Method Update (EMU)
Public Key Infrastructure Using X.509 (PKIX) Working Group
Pseudowire And LDP-enabled Services (PALS) WG Status IETF-93 Prague
Suresh Krishnan Greg Daley
Protocol for Carrying Authentication for Network Access - PANA -
Wednesday, 9:30-12:00 Morning session I, Van Horne
Tuesday , 9:30-12:00 Morning session I, Buckingham
David Noveck IETF99 at Prague July 20, 2017
Distributed Mobility Management Working Group
Los Angeles, California
Chairs: Samita Chakrabarti, Gabriel Montenegro
Chairs: Samita Chakrabarti, Gabriel Montenegro
Tuesday (July 23rd, 2019) Two sessions ( minutes)
SIPBRANDY Chair Slides
IETF 87 DHC WG Berlin, Germany Thursday, 1 August, 2013
Presentation transcript:

SEND WG IETF 57, Vienna Monday, July 14, 9:00 am

Agenda bashing Introduction and Agenda Bashing (5 min.) Chairs Draft Status (10 min.) Chairs Implementation Report (20 min.) Pekka, James IPR discussion (10 min) all, with chairs moderating Open issues in draft-ietf-send-ipsec (20 min) Jari IPsec, IPsec w. CGA Header, or ND options? –ND options (10 min) Jari –IPsec w. CGA header (10 min) Pekka –technical discussion (40 min or until done), all with James moderating Summary and Way Forward (10 min). Chairs

Draft status draft-ietf-send-psreq-03.txt –Intended for Informational RFC –Submitted to IESG at the end of April –IESG review hasn’t started yet draft-ietf-send-ipsec-01.txt –A number of open issues –Biggest issue: IPsec or ND options draft-ietf-send-cga-00.txt –Fairly close to be completed –Some details still need discussion

Implementation reports Jon Wood implemented CGA and RSA transform on Linux Pekka and Gonzalo Camarillo implemented CGA on FreeBSD/KAME –Only basic CGA handling New option to ifconfig Ability to generated CGA IIDs CGA header handling to be added?

Conclusions from Linux implementation work A separate presentation

Conclusion from FreeBSD implementation work Directly mixing CGA and AH is a bad idea –CGA addresses need to be generated at the ND level anyway Generating the first link local address Generating addresses as prefixes are received –Outgoing IPsec SA would become cumbersome Ugly extensions to PF_KEY ifconfig works nicely for configuring CGA PF_KEY would work nicely for pure PK AH

IPR Discussion Ericsson and Microsoft have claimed IPR on Cryptographically Generated Addresses Ericsson released IPRs before IETF56 Microsoft has released IPRs recently No other IPR claims has been received

Open issues A separate presentation

IPsec or ND options Integrating CGA with IPsec got lots of objection Jari Arkko and Tuomas Aura have proposed to move all functionality to ND options Pekka Nikander has proposed to move CGA into a separate extension header Mostly an architectural issue –Should IPsec include PK crypto at AH/ESP at all? This is also the question wrt. source address based SA selection, since PK is source bound –Is in-line KMP allowed? (IPsec WG rejected SKIP) –Should IPsec be used to protect IP layer signalling at all? But first some discussion rules and goals

Rules for discussion Two microphones –First one for primary comments –Second one for followups 3 minutes for each initial comment –After that the commentator must move to the followup microphone Once the discussion is completed, we will perform a concensus call –The concensus call options are on the next slide

Concensus call questions Question 1: If SEND was based on IPsec AH, should we use –a) a large AH header carrying the key (draft-ietf-send-ipsec-01.txt), or –b) separate CGA and AH headers (draft-nikander-send-ipsec-00.txt) Question 2: Should SEND be designed on –a) IPsec AH, using a) or b) from above –b) ND options (draft-arkko-send-ndopt-00.txt)

Summary and Way Forward Continue with ND options Try to get the next version of the draft out before the beginning of September –Probably need to work on certificate issues even after that Need to change the charter Write down the lesson learned about trying to use AH