40 likes | 230 Views
pki4ipsec BOF Architecture Overview. Gregory M Lebovitz gregory@netscreen.com. +---------------------------------------------+ | PKI | | | | +--------------+ |
E N D
pki4ipsec BOFArchitecture Overview Gregory M Lebovitz gregory@netscreen.com
+---------------------------------------------+ | PKI | | | | +--------------+ | | | Repository | +----+ +----+ | | | Certs & CRLs | | CA | | RA | | | +--------------+ +----+ +----+ | | | +---------------------------------------------+ ^ ^ ^ | | | |[E] |[A] |[E] |[M] |[E] |[M] |[R] | |[R] | v | | +----------+ | | [G] | VPN | [G] | | +---------->| Admin |<-------+ | | | | Function | | | | | +----------+ | | v v v v +---------+ +---------+ | VPN | [I] | VPN | | Peer 1 |<=======================>| Peer 2 | +---------+ +---------+ [A] = Authorization [G] = Generation of public/private key pair, certificate request [E] = Enrollment (request and retrieval) [I] = IKE and IPsec communication [M] = Maintenance: validation, revocation, lookups [R] = Renewal (and changes) Figure 1. Architectural Framework for VPN-PKI interaction