Re: WG status 2003/08/13

Pekka Savola <[email protected]> Thu, 14 Aug 2003 16:35:31 +0300 (EEST)
Newsgroups gmane.ietf.itrace
Message-ID <[email protected]>
On Thu, 14 Aug 2003, Marcus D. Leech wrote:
> >  2) iTrace is relatively lightweight, some vendors' ACL implementations
> > can't handle linespeed.  E.g. with STM-16 (2.5 Gbit/s) interface, iTrace
> > might result in some 10-20 iTrace packets a second.  Could be doable even
> > on sloppy CPU's if there are no crypto requirements :-)
>
>
> At 10-20 iTrace packets a second, even with HMAC-MD5, the CPU
> consumption
>   from the HMAC computation will be down in the noise.
> 
> Look at the "Performance Assumptions" section of RFC3562 to get an
>   idea of MD5 performance numbers.

I don't disagree with that, but my main point was that it causes
code/implementation complexity and also some more _operational_ complexity
(configuring certificates/keys, putting them available, etc. -- not so
straightforward as "just turn it on").

Note that CPU's used in some routers are _really_ not that effective 
though, and the vendors may also loath to add functions like these on them 
(in practice, they alsready have to add at least something, for BGP MD5 
implementation).  Just another possible hindrance to implementation and 
deployment (even though probably not a real one).

-- 
Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings