RE: ipSecIfCapsTable not many attributes

<[email protected]> Thu, 15 Apr 2004 14:06:00 -0400
Newsgroups gmane.ietf.ipsp
Message-ID <A6D9D7495456414BA08DB655C2AC67120185BF94@bsebe001.americas.nokia.com>
I agree with Avri. The capability table inside IPsec PIB shall report thi=
ngs that are specific to IPsec PIB. In addition, the framework PIB frwkPr=
cSupportTable and frwkCompLimitsTable together can be used to indicate wh=
at kind of encryptions and algorithms are supported. Hence there seems to=
 be no need to add on the ifSecIfCapsTable.

Best regards
Man Li

> -----Original Message-----
> From: [email protected]
> [mailto:[email protected]]On Behalf Of ext [email protected]
> Sent: Monday, April 05, 2004 11:40 PM
> To: "F=E9lix J.Garc=EDa Clemente"
> Cc: [email protected]
> Subject: Re: ipSecIfCapsTable not many attributes
>=20
>=20
>=20
>=20
> Hi,
>=20
> First let me say how glad I am to hear about another=20
> implementation of=20
> the PIB.
>=20
> My first issue is that since the ID has been through WG last call and=20
> is currently in IESG review and MIB doctor review, I would=20
> not like to=20
> pull it back to add a major new capability for anything less then a=20
> show stopper at this point.
>=20
> Further on the specific issue:
>=20
> While capabilities are important, the Framework PIB has comprehensive=20
> capability mechanism, that should cover the requirements.
>=20
> thanks
>=20
> a.
>=20
> On 2 apr 2004, at 01.49, F=E9lix J.Garc=EDa Clemente wrote:
>=20
> >
> > Hello all,
> > I am including a complete support for the Framework PIB and=20
> the IPSec
> > PIB in my own COPS-PR implementation.
> > I have noted that IPSec PIB includes the table ipSecIfCapsTable to
> > specify capabilities that may be associated with an interface.
> > This table has not many attributes, are you going to add=20
> new attributes
> > or capability tables?
> >
> > I think this is necessary. For example, an interface may not support
> > 'policy reload', i.e. to apply a policy forces to restart the=20
> > interface,
> > or even an attribute may specify the cryptography system supported
> > (symmetric or asymmetric, or both).
> >
> > Regards,
> > F=E9lix
> >
> >
> >
> >
>=20
>=20
>=20