Re: ipSecIfCapsTable not many attributes
"Félix J.García Clemente" <[email protected]> Fri, 16 Apr 2004 11:01:51 +0200
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Message-ID | <[email protected]> |
Hello again, [email protected] wrote: > I agree with Avri. The capability table inside IPsec PIB shall report t= hings that are specific to IPsec PIB. I agree with you. My worry is that currently the capability table inside = IPsec PIB is very simple, I think that new attributes may report more inf= ormation. > In addition, the framework PIB frwkPrcSupportTable and frwkCompLimitsTa= ble together can be used to indicate what kind of encryptions and algorit= hms are supported. For example to indicate that only simmetric encryption is supported, in m= y opinion it seems more simple to add a new attribute in the capability t= able than to build several support and limits tables. Even I think this a= ttribute may be more interesting as capability than as limit. Of course I= can create my own capability tables extending the table ipSecIfCapsTable but it will be 'my' solution. Thanks for your explanation. Regards, F=E9lix > Hence there seems to be no need to add on the ifSecIfCapsTable. > > Best regards > Man Li > > > -----Original Message----- > > From: [email protected] > > [mailto:[email protected]]On Behalf Of ext [email protected]= g > > Sent: Monday, April 05, 2004 11:40 PM > > To: "F=E9lix J.Garc=EDa Clemente" > > Cc: [email protected] > > Subject: Re: ipSecIfCapsTable not many attributes > > > > > > > > > > Hi, > > > > First let me say how glad I am to hear about another > > implementation of > > the PIB. > > > > My first issue is that since the ID has been through WG last call and > > is currently in IESG review and MIB doctor review, I would > > not like to > > pull it back to add a major new capability for anything less then a > > show stopper at this point. > > > > Further on the specific issue: > > > > While capabilities are important, the Framework PIB has comprehensive > > capability mechanism, that should cover the requirements. > > > > thanks > > > > a. > > > > On 2 apr 2004, at 01.49, F=E9lix J.Garc=EDa Clemente wrote: > > > > > > > > Hello all, > > > I am including a complete support for the Framework PIB and > > the IPSec > > > PIB in my own COPS-PR implementation. > > > I have noted that IPSec PIB includes the table ipSecIfCapsTable to > > > specify capabilities that may be associated with an interface. > > > This table has not many attributes, are you going to add > > new attributes > > > or capability tables? > > > > > > I think this is necessary. For example, an interface may not suppor= t > > > 'policy reload', i.e. to apply a policy forces to restart the > > > interface, > > > or even an attribute may specify the cryptography system supported > > > (symmetric or asymmetric, or both). > > > > > > Regards, > > > F=E9lix > > > > > > > > > > > > > > > > > >