Re: no DHCP-assigned InitiatorName

<[email protected]> Mon, 22 Sep 2008 16:18:40 -0500
Newsgroups gmane.ietf.ips
Message-ID <42D8A6CDC96A5A4D8D91DE26991A51AA02016FCC@ausx3mpc108.aus.amer.dell.com>
We should be able to leverage CHAP based security (already defined for
iSCSI) to provide the necessary security (authentication) between the
initiators and targets. 

Thanks,
Gaurav Chawla
Technology Strategist, Network Storage Architecture | Office of the CTO,
Dell, Inc.
Phone: 512.724.4064 (work)


-----Original Message-----
From: Iyer, Shyam 
Sent: Monday, September 22, 2008 3:07 PM
To: Chawla, G; 'Michael Howard'
Cc: '[email protected]'; '[email protected]'; '[email protected]';
'[email protected]'
Subject: RE: [Ips] no DHCP-assigned InitiatorName

Thanks Gaurav. 
You are right. The fact that most of the pre-OS iSCSI initiators don't
have iSNS clients, takes us away from the iSNS scenario atleast for the
boot environment.

On the other hand the scenario where in there are iSNS clients(or a more
enterprise ready environment) we could probably think more on the lines
of security since parameters with DHCP(clear text) is going to be less
secure.

Thanks,
Shyam Iyer

-----Original Message-----
From: Chawla, G 
Sent: Tuesday, September 23, 2008 1:16 AM
To: Michael Howard; Iyer, Shyam
Cc: [email protected]; [email protected]; [email protected];
[email protected]; Chawla, G
Subject: RE: [Ips] no DHCP-assigned InitiatorName

My 2 cents based on my understanding of iSNS. 

- iSNS clients (initiators and targets) need to have an IQN address
before they register with the iSNS server.
- Most pre-OS iSCSI initiators available today are not iSNS clients i.e.
they don't register with and/or query iSNS server.

Given this, it seems better to have a DHCP based standardized mechanism
for acquiring the initiator IQN. Based on initial email from Michael,
most pre-OS iSCSI Initiators available today have the capability to be a
DHCP client.

Thanks,
Gaurav Chawla
Technology Strategist, Network Storage Architecture | Office of the CTO,
Dell, Inc.
Phone: 512.724.4064 (work)


-----Original Message-----
From: [email protected] [mailto:[email protected]] On Behalf Of
Michael Howard
Sent: Monday, September 22, 2008 2:29 PM
To: Iyer, Shyam
Cc: [email protected]; [email protected]; [email protected];
[email protected]
Subject: Re: [Ips] no DHCP-assigned InitiatorName

[email protected] wrote:
> My 2cents on the issue. Please correct me if I am wrong. 

Thank you for participating in this discussion.

> Shouldn't it be possible to configure the isns server with a set of 
> possibly regex rules for the control path. If this not possible today,

> then it could possibly be the root to take towards standardizing.

I am not familiar enough with iSNS to comment.

I have been exposed to about about a dozen commercial environments with
some level of iSCSI use/experimentation. I am not aware that any of them
  were running iSNS servers.

> This can solve the problem of provisioning for dynamic boot 
> environments with minimum changes to legacy iqn implementations, many 
> of which would need to relearn to the new iqn mechanism that might end

> up as a result of this discussion.

Frankly, my concern is that Broadcom/IBM already have a non-standard
DHCP Vendor Option work-around for this problem.

Adding a new/standardized InitiatorName DHCP option would not break
existing initiator implementations. Vendors would integrate support for
this new InitiatorName option into their code/firmware releases over
time.

> Instead of changing numerous configurations we could simply change the

> isns server control mechanism.

I need to do some homework regarding iSNS.

> Comments?

iSCSI is still a very small part of the market.

I advocate addressing this deficiency sooner rather than later.


Michael
_______________________________________________
Ips mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ips
_______________________________________________
Ips mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ips