Re: Racoon not synchronizing keys? (was: none)

From: Barry Irwin (bvi@itouchlabs.com)
Date: 05/22/02


Date: Wed, 22 May 2002 14:46:12 +0200
From: Barry Irwin <bvi@itouchlabs.com>
To: Thomas Fritz <tf@slash10.com>

The short, but not quite so perfect answer, is to adjust the lifeimes in
your racoon.conf. There are two lifetimes, the IKE lifetime which can be
kept short ( like 60 seconds) as this is only used for covering the
negotiation of keys for the IPSEC SA's. The IPSEC SA is the second
lifetime, the suggestions are that this should be kept fairly short, as each
time the keys are changed, it reduces the window of opportunity that an
intruder has to view your data. However, by keeping thse short as well, you
would have to wait on average n/2 time units for the IPSEC SA to expire, and
to be re-negotaited.

One thing I have seen is the explicit KEY_EXPIRE message in the racoon debug
logs. Would be nice to know how to send these explicity :-)

Okay, not as helpful as I intended, but worth voicing anyway.

Barry
 

On Wed 2002-05-22 (10:51), Thomas Fritz wrote:
> Hi again!
>
> Forgot the subject the first time...
>
> I already got an answer to my question, which stated,
> that I should use manual keys instead.
>
> But that's not an option for me.
>
> Is there really no other solution?
>
> Thanks
> /tom
>
>
> >Hi there!
> >
> >On the URL http://www.onlamp.com/pub/a/bsd/2001/12/10/ipsec.html I found
> >this warning below:
> >
> >One other word of warning -- if you reboot one of the hosts, and suddenly
> >have connectivity problems, flush the keys on both machines by running
> >setkey -F. It's possible for the keys to get out of sync.
> >
> >
> >Is there any way to overcome this problem without flushing the keys by hand?
> >
> >
> >Thanks in advance
> >
> >/tom
>
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the message
>
>

--
Barry Irwin		bvi@itouchlabs.com			+27214875177
Systems Administrator: Networks And Security
Itouch Labs 		http://www.itouchlabs.com		South Africa
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • HashMap Capacity Argument.
    ... I want to create a HashMap. ... I know before hand the total number of keys ... that I will place into it during its lifetime. ... Prev by Date: ...
    (comp.lang.java.help)
  • Re: IPSEC interoperability with Win2K client?
    ... w2k with racoon and ipsec works. ... dialin server on freebsd. ... IPSEC interoperability with Win2K client? ... > of keys isn't possible - all keys signed by approved CA are ...
    (FreeBSD-Security)
  • Re: IPsec von Debian Sarge nach WatchGuard: NO-PROPOSAL-CHOSEN
    ... Das übliche Bild bei heterogenem IPsec;) ... Resource temporarily unavailable" und racoon ... lifetime time 4 hours; ...
    (de.comp.os.unix.networking.misc)
  • Re: How safe us my wireless network
    ... because the payload isn't encrypted anymore. ... IPSec works on Layer IP your tcp packet is encrypted and if you use AH ... keys, keys, keys.... ... scared to do banking online, purchase over the internet, etc... ...
    (comp.security.firewalls)
  • Re: 56bit encryption worthless?
    ... >I am fairly sure that IPsec and also the protocol used for wireless ... IPsec can uses a variety of protocols (e.g., ... bit keys) but more the way in which the cipher is used. ... to opinions held by my employer, Sun Microsystems. ...
    (comp.security.misc)