Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature request: Data-Plane Confidentiality #14

Open
renne opened this issue Oct 8, 2017 · 1 comment
Open

Feature request: Data-Plane Confidentiality #14

renne opened this issue Oct 8, 2017 · 1 comment

Comments

@renne
Copy link

renne commented Oct 8, 2017

Payload encryption makes LISP a highly flexible VPN solution with e.g. multi-homing, roaming, etc.

Please add support for IETF RFC 8061 to OpenOverlayRouter.

@albert-lopez
Copy link
Member

Thanks for your suggestion, we strongly believe that security is a
missing feature in OOR but we are not satisfied with LISP-CRYPTO,
since it only offers confidentiality but not authentication (it uses a
Diffie-Hellman key exchange through the MS), as such it is vulnerable
against man-in-the-middle attacks compromising the confidentiality.

We are in the process of discussing this internally to see how to fix
such issues and provide a fully-featured security solution, but this
will take some time.

As always we are more than happy to welcome any community member
willing to contribute

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants