RE: ipSecIfCapsTable not many attributes
<[email protected]> Thu, 15 Apr 2004 14:06:00 -0400
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Message-ID | <A6D9D7495456414BA08DB655C2AC67120185BF94@bsebe001.americas.nokia.com> |
I agree with Avri. The capability table inside IPsec PIB shall report thi= ngs that are specific to IPsec PIB. In addition, the framework PIB frwkPr= cSupportTable and frwkCompLimitsTable together can be used to indicate wh= at kind of encryptions and algorithms are supported. Hence there seems to= be no need to add on the ifSecIfCapsTable. Best regards Man Li > -----Original Message----- > From: [email protected] > [mailto:[email protected]]On Behalf Of ext [email protected] > Sent: Monday, April 05, 2004 11:40 PM > To: "F=E9lix J.Garc=EDa Clemente" > Cc: [email protected] > Subject: Re: ipSecIfCapsTable not many attributes >=20 >=20 >=20 >=20 > Hi, >=20 > First let me say how glad I am to hear about another=20 > implementation of=20 > the PIB. >=20 > My first issue is that since the ID has been through WG last call and=20 > is currently in IESG review and MIB doctor review, I would=20 > not like to=20 > pull it back to add a major new capability for anything less then a=20 > show stopper at this point. >=20 > Further on the specific issue: >=20 > While capabilities are important, the Framework PIB has comprehensive=20 > capability mechanism, that should cover the requirements. >=20 > thanks >=20 > a. >=20 > On 2 apr 2004, at 01.49, F=E9lix J.Garc=EDa Clemente wrote: >=20 > > > > Hello all, > > I am including a complete support for the Framework PIB and=20 > the IPSec > > PIB in my own COPS-PR implementation. > > I have noted that IPSec PIB includes the table ipSecIfCapsTable to > > specify capabilities that may be associated with an interface. > > This table has not many attributes, are you going to add=20 > new attributes > > or capability tables? > > > > I think this is necessary. For example, an interface may not support > > 'policy reload', i.e. to apply a policy forces to restart the=20 > > interface, > > or even an attribute may specify the cryptography system supported > > (symmetric or asymmetric, or both). > > > > Regards, > > F=E9lix > > > > > > > > >=20 >=20 >=20