Draft Minutes, for review
"The Purple Streak, Hilarie Orman" <[email protected]>
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Message-ID | <[email protected]> |
These are the draft minutes from the recent IPSP meeting; please send changes to the chairs (Hilarie Orman, [email protected]; Luis Sanchez, xapiens.com). The minutes will be posted for the proceedings next week. ------------------- Minutes of IPsec Policy, IPSP, 55th IETF, Monday, November 18, 3:30 pm EST The meeting opened with agenday bashing and a status of the WG documents. The policy configuration documents are within episilon of being ready to present to the IESG for a request for promotion to Proposed Standard. Other Working Group items need discussion and decisions about direction. Security Area Director, Steve Bellovin verified that he alone has looked at the submitted documents and he provided feedback to the document authors. The IESG as a whole has not yet seen them. The AD comments are summarized in the Chairs' presentation. One attendee asked if AES must be added to the supported algorithms list, and the answer was yes. Another was whether or not the lifetime counters should be specified at 64-bits in the IPsec architecture document. The answer is no, but we should make sure that the IPsec group is aware of the need to match the lifetime counter size to the linespeed. For configuration, we have chosen 64-bits because it is large enough for all expected needs. Eric Vyncke presented the IPsec Configuration Policy Model status. Steve Bellovin commented that he expects the WG's in the security area to have expertise for writing good security considerations sections. Luis Sanchez replied that the applicable contents of the first version of the IPSP Architecture document will be added to the security considerations section of the IPCM draft. The ICPM revisions based on AD feedback will be incorporated and the document will be resubmitted very soon. The WG Chairs will notify the AD when the new documents are available, and this will alert him to begin tracking the document through the IESG document tracker. Robert Story presented a summary of the MIB document. It is nearly done, and the AD comments on the other documents will be addressed in this document as well. The next version will be available very soon. An informal poll showed that a handful of attendees are planning to use PIBs or MIBs in projects in the very near future. He gave the following information about the MIB and the implementation status: - MIB is now handled by Robert Story from Freesnmp together with Wes Hardaker and Russ Mundy from TISlabs, they also added normative/informative references. - reference implementation on http://net-policy.sourceforge.net for Linux and PlutoPlus + Apache + perl for GUI - MIB extended the ICPM with generic offset in the iPHeaderFilter Bill Sommerfield presented the PF_POLICY concept, which is one part of a three-part API for IPSec: IPSec management, PF_POLICY, PF_KEY. He was asked several questions about how PF_KEY might change and what the status of documentation and implementation is. He said that some minor parts of the implementation were done and that he needed time to write up the documentation. He got a volunteer to assist in writing a requirements document. We can expect a document on PF_POLICY by second quarter 2003. Michael Richardson re-presented slides about policy discovery. We need further discussion on the mailing list about how this might be used for enterprise and ISP scenarios. Luis Sanchez reviewed the WG charter. He pointed out accomplished WG items (requirements, Confifuration Model, PIB and MIB) already and noted that we need to update our milestone dates. Meeting ended.