Re: Question about IPsec in IPv6

2003-01-20 Thread Francis Dupont
In your previous mail you wrote: I want to know if there have been made additions to the IPsec part on IPv6. Something that bugs me to Ipsec on IPv4 is that it either required some system backed authentication (Kerberos), some CA issued certificate or the worst solution being a

RE: Question about IPsec in IPv6

2003-01-20 Thread Mario Goebbels
= I disagree: without authentication (by a pre-shared secret, certificate/signature or public key) you can be attacked by the Man-In-The-Middle, i.e., you can get a very secure connection with a bad guy, not the intended correspondent. There are some schemes where one participant can be

Re: Question about IPsec in IPv6

2003-01-20 Thread Francis Dupont
In your previous mail you wrote: = I disagree: without authentication (by a pre-shared secret, certificate/signature or public key) you can be attacked by the Man-In-The-Middle, i.e., you can get a very secure connection with a bad guy, not the intended correspondent.