Great Circle Associates Firewalls
(October 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Encryption strength
From: Rick Smith <smith @ sctc . com>
Date: Wed, 4 Oct 1995 09:42:35 -0500
To: firewalls @ greatcircle . com
Cc: smith @ sctc . com
References: <9510040306 . AA12903 @ su1 . in . net>

frankw @
 in .
 net (Frank Willoughby) says:

>>>Actually, the key management problem was solved by V-ONE a couple of years
>>>ago. (V-ONE is a firewall vendor).  

>Padgett asks the obvious:
>>Sounds wonderful but pray tell *how* do they authenticate each other ?

>So Frank rites:
>Would it suffice to say that it was good enough for NSA - and that it is the 
>*only* Internet firewall used in a NSA-approved configuration?  In a public
>forum, this is probably all I can say.

Interesting. The only "approved configuration" I know of wasn't so
much NSA as DISA, and the cryptographic services were irrelevant to
its application. If you really do know of an "approved configuration"
involving crypto on a commercial firewall, then there are at least
*two* different "approved configurations" out there.

There have been several "solutions" to the "key management problem,"
and so far nobody, not even NSA, has come up with one that solves
everything. Choosing a key management scheme is just like any other
big mechanism decision: it depends on what your threats and
operational objectives are. PGP takes one approach yielding one set of
results, FORTEZZA takes another.

It is true that we can't pick apart the details of whatever these
government configurations *are* in a public forum. However, I suspect
that any 2 year old commercial implementation is probably at most
proprietary information. Most likely there's a public whitepaper
describing what V-One does, and how.  If V-One (or its crypto
implementer) is represented on this list, it might be interesting to
hear a first hand report of what they really achieve.

Rick.
smith @
 sctc .
 com           secure computing corporation


References:
Indexed By Date Previous: re: Encryption Strength
From: "A. Padgett Peterson, P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>
Next: Network Address Translation stuff
From: Mike Shaver <shaver @ neon . ingenia . com>
Indexed By Thread Previous: re: Encryption strength
From: frankw @ in . net (Frank Willoughby)
Next: re: Encryption Strength
From: "A. Padgett Peterson, P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>

Google
 
Search Internet Search www.greatcircle.com