End-to-end... and everything in between

Dan McDonald's Sun blog, covering IPsec, general networking goodness, and other stuff too.


20060307 Tuesday March 07, 2006

ESP without authentication considered harmful Hopefully you will read this and go "That's obvious". I'm writing this entry, however, for those who don't.

When IPsec was being specified over 10 years ago, attacks against cipher-block-chaining (CBC) encryption were understood. ESP has an authentication algorithm because AH had a vocal-enough opposition to merit having packet integrity in ESP also (there are also performance arguments for ESP-auth).

Now there actual attacks with actual results. Kenny Paterson and Arnold Yau have published a paper with attacks against no-authentication ESP Tunnel Mode. I believe some of the techniques can also be employed against Transport Mode as well, but again, only with no authentication present.

The simple solution, of course, is to employ your choice of ESP Authentication (encr_auth_algs in ipsecconf(1m) or ifconfig(1m)) or AH (auth_algs in ipsecconf(1m) or ifconfig(1m)) with your IPsec deployment. We warn users about such configurations with ifconfig(1m) today. There is an RFE to eliminate or make very difficult encryption-only configurations in Solaris. Maybe someone in the OpenSolaris community would like to take a stab at it? [EDITED to correct Kenny's last name.] (2006-03-07 11:17:07.0) Permalink Comments [2]

Trackback URL: http://blogs.sun.com/danmcd/entry/esp_without_authentication_considered_harmful
Comments:

Hi Dan, There's one "t" in "Paterson"! Cheers, Kenny

Posted by 86.143.36.42 on March 07, 2006 at 04:52 PM EST #

I just fixed it. Sorry about that.

Posted by Dan McDonald on March 14, 2006 at 12:40 PM EST #

Post a Comment:

Name:
E-Mail:
URL:

Your Comment:

HTML Syntax: NOT allowed

Calendar

« November 2009
SunMonTueWedThuFriSat
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
24
25
26
27
28
29
30
     
       
Today

RSS Feeds

XML
All
/Entertainment
/IPsec
/Miscellany
/Networking

Search

Links




Navigation



Referers

Today's Page Hits: 240