SKEX Agenda
IETF 122 [hybrid] Bangkok
Wednesday 19 March 2025
02:30 (UTC)/09:30 (Bangkok), 2 hours
Meetecho:
https://meetings.conf.meetecho.com/ietf122/?group=skex&short=&item=1
Notes: https://notes.ietf.org/notes-ietf-122-skex
Chairs: Yaron Sheffer and Alexey Melnikov
Slides:
https://datatracker.ietf.org/meeting/122/materials/slides-122-skex-presentation-slides-v03-00
Issues enumerated with Kerberos.
No scalable symmetric key establishment without a central "all
knowing" authority
Need a quantum safe, efficient scalable solutions that PKC and PQC
fail to address.
Stephen Farrell - Not best approach to say Kerberos is wrong. Is
this motivated by QKD.
Unidentified speaker
Hannes Tschoffeninig
Thom Wiggers
Daniel Shiu
Eric
Tirumalseswar
Hooman: We are not here to challenge PKI
MACsec + MKA Key Distribution for critical infrastructure.
Eric
Viktor
Hannes
Why can't the existing approaches be used? Impression is
other options have not been considered.
Use case was not clearly represented.
IoT is not really a use case
Wei Pan
What is the problem
There is a long history of problems with pre-shared key
distribution - this is why Kerberos exist.
Have you tried Kerberos in your system
Kerberos is fine, you just want something else?
What are you solving
Want to standardise MKAoIP?
Key problem is not key distribution (Kerberos)
What is the Problem
Tirumalseswar
Bob Moskowitz
Highlights cost and challenges of PKI
Bob - needs a new cert every flight. This is a process
problem.
Christopher Wood
What happens if first pre shared key is compromised?
Pre-shared keys are looking back, there are better solutions
Not broken - irrelevant - this is not how we reason over
security
The charter was not read out or discussed.
Only one question was asked:
Is the Problem clear, well scoped and useful to solve
1. Yes 24
2. No 44
3. No Opinion 5
The chairs did not determine consensus, either way.
No further questions.
Paul (AD)