Problem and Applicability Statement for Better-Than-Nothing Security
RFC 5387, “Problem and Applicability Statement for Better-Than-Nothing Security”, is an Informational document published in November 2008 by J. Touch, D. Black, Y. Wang. The canonical text is published by the RFC Editor.
Abstract
The Internet network security protocol suite, IPsec, requires authentication, usually of network-layer entities, to enable access control and provide security services. This authentication can be based on mechanisms such as pre-shared symmetric keys, certificates with associated asymmetric keys, or the use of Kerberos (via Kerberized Internet Negotiation of Keys (KINK)). The need to deploy authentication information and its associated identities can be a significant obstacle to the use of IPsec.
This document explains the rationale for extending the Internet network security protocol suite to enable use of IPsec security services without authentication. These extensions are intended to protect communication, providing "better-than-nothing security" (BTNS). The extensions may be used on their own (this use is called Stand-Alone BTNS, or SAB) or may be used to provide network-layer security that can be authenticated by higher layers in the protocol stack (this use is called Channel-Bound BTNS, or CBB). The document also explains situations for which use of SAB and/or CBB extensions are applicable. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 5387 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5386 Better-Than-Nothing Security: An Unauthenticated Mode of IPsec
- RFC 5388 Information Model and XML Data Model for Traceroute Measurements
- RFC 5389 Session Traversal Utilities for NAT
- RFC 5384 The Protocol Independent Multicast Join Attribute Format
- RFC 5390 Requirements for Management of Overload in the Session Initiation Protocol
- RFC 5383 Deployment Considerations for Lemonade-Compliant Mobile Email
- RFC 5391 RTP Payload Format for ITU-T Recommendation G.711.1
- RFC 5382 NAT Behavioral Requirements for TCP