08-06-2013 04:51 AM - edited 02-21-2020 07:04 PM
It's not specified how Key Servers react when many group members leave at the same time. For example, if 3 members leave a same group, did the key manager sends three keys (KEK,TEK), and only the last one will be available for future connections ? Or did the key manager optimizes the rekeying and sends only one key ?
Thanks
Solved! Go to Solution.
08-08-2013 02:59 AM
Pierre,
On itself it's not insecure. You can extract the session keys from memory (not impossible but tricky).
I guess what you're looking for is a red button to clear SAs on all devices?
In which case:
Specifically "clear crypto gdoi ks members now"
Was there any particular risk you were thinking about?
M.
08-07-2013 06:58 AM
Pierre,
TEK and KEK (for the most part) do not change during their lifetime.
A change of state of a particular GM does not affect TEK used by other peers.
M.
08-08-2013 02:16 AM
Thanks for your answer Marcin,
So, that means if a member leave his group, he will be able to read messages of his old group until the life-time of the TEK expires ? It's a little bit unsecure, isn't it?
Pierre
08-08-2013 02:59 AM
Pierre,
On itself it's not insecure. You can extract the session keys from memory (not impossible but tricky).
I guess what you're looking for is a red button to clear SAs on all devices?
In which case:
Specifically "clear crypto gdoi ks members now"
Was there any particular risk you were thinking about?
M.
08-08-2013 04:35 AM
That's what i was looking for, thanks very much. I thought that all SAs were cleared by default when a gm leave.
Thanks again, have a nice day.
Pierre
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide