HP-UX IPSec Overview

Authentication Header (AH)

the values match, the recipient is assured that the sender knows the same secret key, confirming the identity of the sender. The recipient is also assured that the data was not altered during transit.

Figure 1-1Symmetric Key Authentication

 

 

 

 

 

 

 

 

 

 

 

 

 

Host A

 

 

 

 

 

 

Host B

 

 

 

 

 

 

 

 

 

 

Shared Key

 

 

 

 

 

 

 

 

 

Plaintext

 

 

authentication

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

value

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

hash

 

 

 

 

 

 

hash

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Shared Key

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Plaintext

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

authentication

 

 

 

 

 

 

 

 

 

value

 

 

 

 

Plaintext

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

authentication

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

value

 

 

 

 

 

 

(compare)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

HP-UX IPSec supports the following algorithms for AH:

HMAC-SHA1(Hashed Message Authentication Code-Secure Hash Algorithm 1, 128-bit key)

HMAC-MD5(HMAC-Message Digest 5, 160-bit key)

Transport and Tunnel Modes

The IPSec headers (AH and ESP) can be used in transport mode or tunnel mode.

Transport Mode

In transport mode, IPSec inserts the AH header after the IP header. The IP data and header are used to calculate the AH authentication value. Mutable fields in the IP header (fields that need to change in transit), such as “hop count,” and “time to live,” are assigned a zero value before IPSec calculates the authentication value, so the actual value of the mutable fields are not authenticated.

30

Chapter 1