Kristof Teichel, Dieter Sibold, Daniel Franke Network Time Security draft-ietf-ntp-network-time-security-15 draft-ietf-ntp-using-nts-for-ntp-07 Kristof Teichel, Dieter Sibold, Daniel Franke
NTS: WGLC Design Team Progress WGLC generated large amounts of feedback Led to creation of the NTS Design Team Latest proposals developed at NTP WG Interim (Oct 2016) regarding draft-ietf-ntp-using-nts-for-ntp-07 Key exchange Privacy (NTS shall not leak information suitable to track a NTP client) Peer mode (DTLS payload) Nov 13-18, 2016 IETF 97, Seoul, South Korea
Key Exchange Mode Key Exchange KE Port / Transport NTP Packet Transport Port / Transport Mode 1 & 2 DTLS UDP / ??? as DTLS payload Mode 3 & 4 TLS TCP / ??? NTP Packet with NTS extensions UDP / 123 Mode 6 DTLS/TLS UDP/TCP/ ??? as (D)TLS payload UDP/TCP/??? Piggy backing DTLS KE over NTP (within extension fields) is postponed Optional key exchange mechanism are not allowed for NTS for NTP Nov 13-18, 2016 IETF 97, Seoul, South Korea
Open Issues/Questions ASN.1 versus ad hoc binary encoding versus something else? What to do with non-NTP-specific NTS document (draft-ietf-ntp-network-time-security)? Was intended to provide protection schemes for unicast and broadcast/multicast time sync messages (NTP and PTP) Until now very limited feedback on the NTS messages for broadcast/multicast time sync messages IEEE P1588 WG security subcommittee is specifying a security scheme for PTP Nov 13-18, 2016 IETF 97, Seoul, South Korea
Next Steps draft-ietf-ntp-using-nts-for-ntp: draft-aanchal4-ntp-mac-00 Next Steps draft-ietf-ntp-using-nts-for-ntp: Client/Server associations: TLS instead of DTLS Privacy considerations: Attack vector for active monitoring Security Considerations Revision of the section “Usage of NTP Pools” draft-ietf-ntp-network-time-security: Adapt this draft (if desired) Nov 13-18, 2016 IETF 97, Seoul, South Korea