[29909] in bugtraq
Re: Cracking preshared keys
daemon@ATHENA.MIT.EDU (hank@mail.iucc.ac.il)
Fri Apr 25 17:23:01 2003
Date: 25 Apr 2003 06:48:24 -0000
Message-ID: <20030425064824.13022.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: <hank@mail.iucc.ac.il>
To: bugtraq@securityfocus.com
In-Reply-To: <4.3.2.7.2.20030423203906.06148110@ca-uk-fs.cisco.com>
A friend of mine from Checkpoint has told me that this is not totally
correct and due to many political issues within the different IETF task
forces CheckPoint's Hybrid mode was never made into an RFC.
See:
http://www.ietf.org/proceedings/99nov/I-D/draft-ietf-ipsec-isakmp-hybrid-
auth-02.txt for more details.
-Hank
>Weak authentication in Xauth and IKE). The IPSec Working Group has=20
>understood and acknowledged this attack avenue, but has deemed that=20
>this is an acceptable risk.
> Gaus