[Nea] Comments on NEA TNC protocols
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Nea] Comments on NEA TNC protocols



Here are my general comments:
 

General:

 

 

 

For replay detection, it appears that the initial message is not protected (this may not be a problem).  If there are multiple parties involved in the exchange it is not clear how the nonce is generated and validated.

 

Further, the addition of a capabilities discovery is eluded to in the draft, but the details are unclear or inconsistent.  Section 2.4 mentions “The algorithm list is encapsulated within a signed CMS message that the recipient can use to verify the authenticity and integrity of the algorithm”, but given the group nature of the PA and a discovery of capabilities, its unclear how a signature can be imposed in the message for proper validation if the appropriate trust anchors has not been established.  Can other algorithms be explored beyond RSA for signing and ECDSA for validation (these are very computationally expensive).  A state or process flow diagram should be provided, or at minimum a description

 

 

 

  Nancy.
_______________________________________________
Nea mailing list
Nea at ietf.org
https://www.ietf.org/mailman/listinfo/nea

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.