[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

ISAKMP/Oakley does not allow negotiation on PFS requirement.




With ISAKMP/Oakley, we have a choice of requiring PFS. However, it does not provide
any means of negotiating PFS.

So, if initiator would prefer that PFS is not a requirement, but will accommodate responders
desires for PFS, there is no easy way of communicating this to the responder.

In this situation, initiator has no choice but to require PFS. If it does include KE in the 
phase 2 message, responder will assume that PFS is required by initiator. If it does
not include KE in the message, and responder requires PFS, phase 2 fails.

It is my opinion that as part of the ISAKMP/Oakley SA negotiation, the requirements for 
PFS must be negotiated. So that before starting phase 2, the communicating peers know
each others requirements for PFS and agree upon on that is acceptable to both.

Baiju



Follow-Ups: