Re: ipSecIfCapsTable not many attributes

"Félix J.García Clemente" <[email protected]> Fri, 16 Apr 2004 11:01:51 +0200
Newsgroups gmane.ietf.ipsp
Message-ID <[email protected]>
Hello again,

[email protected] wrote:

> I agree with Avri. The capability table inside IPsec PIB shall report t=
hings that are specific to IPsec PIB.

I agree with you. My worry is that currently the capability table inside =
IPsec PIB is very simple, I think that new attributes may report more inf=
ormation.

> In addition, the framework PIB frwkPrcSupportTable and frwkCompLimitsTa=
ble together can be used to indicate what kind of encryptions and algorit=
hms are supported.

For example to indicate that only simmetric encryption is supported, in m=
y opinion it seems more simple to add a new attribute in the capability t=
able than to build several support and limits tables. Even I think this a=
ttribute may be more interesting as capability than as limit. Of course I=
 can create my own capability tables extending
the table ipSecIfCapsTable but it will be 'my' solution.

Thanks for your explanation.
Regards,
F=E9lix

> Hence there seems to be no need to add on the ifSecIfCapsTable.
>
> Best regards
> Man Li
>
> > -----Original Message-----
> > From: [email protected]
> > [mailto:[email protected]]On Behalf Of ext [email protected]=
g
> > Sent: Monday, April 05, 2004 11:40 PM
> > To: "F=E9lix J.Garc=EDa Clemente"
> > Cc: [email protected]
> > Subject: Re: ipSecIfCapsTable not many attributes
> >
> >
> >
> >
> > Hi,
> >
> > First let me say how glad I am to hear about another
> > implementation of
> > the PIB.
> >
> > My first issue is that since the ID has been through WG last call and
> > is currently in IESG review and MIB doctor review, I would
> > not like to
> > pull it back to add a major new capability for anything less then a
> > show stopper at this point.
> >
> > Further on the specific issue:
> >
> > While capabilities are important, the Framework PIB has comprehensive
> > capability mechanism, that should cover the requirements.
> >
> > thanks
> >
> > a.
> >
> > On 2 apr 2004, at 01.49, F=E9lix J.Garc=EDa Clemente wrote:
> >
> > >
> > > Hello all,
> > > I am including a complete support for the Framework PIB and
> > the IPSec
> > > PIB in my own COPS-PR implementation.
> > > I have noted that IPSec PIB includes the table ipSecIfCapsTable to
> > > specify capabilities that may be associated with an interface.
> > > This table has not many attributes, are you going to add
> > new attributes
> > > or capability tables?
> > >
> > > I think this is necessary. For example, an interface may not suppor=
t
> > > 'policy reload', i.e. to apply a policy forces to restart the
> > > interface,
> > > or even an attribute may specify the cryptography system supported
> > > (symmetric or asymmetric, or both).
> > >
> > > Regards,
> > > F=E9lix
> > >
> > >
> > >
> > >
> >
> >
> >