2002 Linux Symposium
navigation



related

contact:

Opportunistic Encryption with Linux FreeS/WAN

Claudia Schmeing

Linux FreeS/WAN's Opportunistic Encryption (OE) is IPsec to any willing host, using public keys distributed via DNS. OE is currently useful primarily to prevent passive snooping of IP traffic. Its main advantage over traditional IPsec configuration (for example, using shared secrets) is that it does not require prearrangement between system administrators at each end of a potential IPsec connection. We will demonstrate OE by publishing keys in DNS and using those keys to establish a Linux FreeS/WAN connection with minimal configuration. We will then show how a sysadmin might use OE to set local IPsec security policy using FreeS/WAN's "policy groups" configuration mechanism. In the process, we will discuss challenges that OE presents to traditional notions of trust in IPsec peers. Last, we will discuss the future of OE: integrating OE with DNSsec authentication. If time permits, we may also demonstrate WAVEsec (www.wavesec.org), a related use of IPsec which also relies on key distribution via DNS.
2004
© 1999-2003 Linux Symposium.  All Rights Reserved.