Re: WGLC on the design draft

Tero Kivinen <[email protected]> Thu, 5 Jan 2006 14:33:20 +0200
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Francis Dupont writes:
> >    We are now talking about the IPsec. As far as I know those RFCs only
> >    cover MOBILE IP case, thus they are not generic IPsec solutions. I
> >    might be wrong, as I have not followed what was done there. 
>    
> I agree, IMHO the word "internal" (to IPsec) or something equivalent
> is enough, for instance "Existing IPsec documents" works well.

Changed to that "Existing IPsec document ...". 

> so the text should be more accurate about what it calls load balancing,
> i.e., why not add this definition in the terminology section? (the idea is
> the document may use what it likes as soon as it is either a common
> term or a defined-within term).

Most comments have been that would need to remove extra terms from the
terminology section, so I do not think we need to add one more, that
is only in 1-2 places in the document. 

> no, ranges don't make sense with pseudo-random values.

There are implementations who do allocate SPI values in groups, where
ranges makes perfect sense for the implementation allocating the SPIs.
For the other end ranges does not mean anything, but it does compress
the list of SPIs much smaller if SPI values are allocated knowing the
fact. 

> RFC 4302 says "arbitrary value". I am not convinced there is no
> attack against predictable SPIs. As far as I know all
> implementations use (pseudo) random SPIs... This is what I assume
> when I say ranges don't make sense there.

RFC4302 also says:

      However, the
      creator of an SA may choose to interpret the bits in an SPI to
      facilitate local processing.

which means that allocating SPIs of the high bandwidth SAs from range
0xe0000000-0xefffffff, and SPIs of the low bandwidth high availibility
SAs from range 0xd000000-0xdfffffff, would still be completely aligned
with the RFC4302. The idea is that SPI is arbitrary number and only
creator of the SPI can know why certain value was used.

Also SPIs allocated from those 24 bit ranges are still not
predictable. I still do not completely how you want to modify that
text, i.e. what is more efficient format than list of ranges that you
want to mention there?

> I am not against this "authority" argument, my concern is about a
> poor argumentation to defend the decision, i.e., I strongly suggest
> to remove the whole argumentation and just to say it is the WG
> decision.

The text there is not there to "defend" the decision, it is there for
background information, and to explain that we did consider these
things, and that we made this decision.

If you have better arguments for either side, feel free to submit
them, I can add them there too. 
-- 
[email protected]