|
Sun tries to SKIP the competition
Promotes key-exchange protocol over IETF's rival spec
By Jim Kerstetter and Claudia Graziano, PC Week Online
02.16.98
Sun Microsystems Inc. will begin an all-out push this week to raise the profile of its key-exchange protocol.
The SKIP (Simple Key management for Internet Protocols) specification, which defines the way an encryption key is exchanged between two parties over the Internet, was released nearly two years ago, embedded in Solaris and other products.
But it failed to gain the favor of the Internet Engineering Task Force, which is using another key-exchange method--ISAKMP (Internet Security Association and Key Management Protocol)/Oakley Key Determination Protocol--for the proposed IPSec (IP Security) protocol for virtual private networks.
This week, a long list of companies, including Novell Inc., Internet Dynamics Inc., Check Point Software Technologies Ltd., OpenRoute Networks Inc., Toshiba Corp. and VPNet Technologies Inc., will announce plans to work with SKIP, said sources close to the companies.
Security administrators say SKIP has a distinct advantage over other key-exchange methods: maturity. "But on the other hand, we're still in the evaluation stage for our PKI [public-key infrastructure], so there's no rush," said a manager at an international financial corporation.
Novell, in Provo, Utah, will announce that the next release of its BorderManager firewall will support SKIP. It will preview the SKIP support at its BrainShare conference next month in Salt Lake City and will release it by midyear, sources said. Novell also will support IPSec (which can still work with SKIP) and the key-exchange mechanism that is being written into the proposed IPSec standard, ISAKMP/Oakley.
Sun officials in Palo Alto, Calif., declined to comment last week, but they have in the past questioned why the IETF picked ISAKMP/Oakley, a new specification that is only now receiving support in security products, over SKIP.
IPSec works at the IP network layer and is supposed to be less obtrusive to the end user. It makes IP packets secure by encrypting them with a choice of algorithms and then sends them to another IPSec-compliant device on the receiving end.
SKIP, which does not require compliant devices on both ends, can be plugged into the IPSec spec. Sources said that Sun wants to push SKIP as a de facto key- exchange standard before products that use ISAKMP/Oakley hit the market.
Other companies lining up behind Sun are expected to make similar public statements this week. Toshiba's Computer and Network product division, of Tokyo, will announce that a version of its Network CryptoGate VPN (virtual private network) software, due by midyear, will support SKIP.
OpenRoute Networks, of Westboro, Mass., will integrate SKIP into its suite of VPN products. Internet Dynamics, in Smyrna, Ga., will announce that it already supports SKIP in its VPN suite. Check Point, of Redwood City, Calif., and VPNet, of San Jose, Calif., will make similar announcements regarding their firewall lines.
|
Simple Key management for Internet Protocols
What is it?
A protocol that allows users to create encrypted channels across an IP network
What does it offer?
Allows security to be built into applications
Who plans to support it?
Sun, Novell, Internet Dynamics, Check Point, OpenRoute Networks, Toshiba, VPNet
|
|
|
|