[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Definition of PFS...



>   It also defends against the situation where a third party compels one
> party to provide some set of keys. PFS guarantees that a simple search warant
> only catches traffic *currently* in transit, not all previous and future
> traffic.

Not quite that simple; it's a matter of what the lifetimes of the IKE
and AH/ESP SA's really are..

If your AH/ESP SA lifetimes are 12 hours, this gives someone 12 hours
of traffic even if quick mode with PFS was used to create them.

Similarly, if you don't use PFS in quick mode, but limit your IKE SA's
(and the AH/ESP SA's derived from them via quick mode) to a lifetime
of 1 hour, you get 1 hour of traffic.

					- Bill


Follow-Ups: References: