Question about IPsec in IPv6

2003-01-20 Thread Mario Goebbels
Hi! I want to know if there have been made additions to the IPsec part on IPv6. Something that bugs me to Ipsec on IPv4 is that it either required some system backed authentication (Kerberos), some CA issued certificate or the worst solution being a static keyphrase. Now to my question: Does IPsec

Re: Question about IPsec in IPv6

2003-01-20 Thread Francis Dupont
In your previous mail you wrote: I want to know if there have been made additions to the IPsec part on IPv6. Something that bugs me to Ipsec on IPv4 is that it either required some system backed authentication (Kerberos), some CA issued certificate or the worst solution being a static

RE: Question about IPsec in IPv6

2003-01-20 Thread Mario Goebbels
> => I disagree: without authentication (by a pre-shared > secret, certificate/signature or public key) you can be > attacked by the Man-In-The-Middle, i.e., you can get a very > secure connection with a bad guy, not the intended > correspondent. There are some schemes where one participant >

Re: Question about IPsec in IPv6

2003-01-20 Thread Francis Dupont
In your previous mail you wrote: > => I disagree: without authentication (by a pre-shared > secret, certificate/signature or public key) you can be > attacked by the Man-In-The-Middle, i.e., you can get a very > secure connection with a bad guy, not the intended > correspondent