Re: draft-nordmark-multi6-threats-01.txt
Brian E Carpenter <[email protected]>
| Newsgroups | gmane.ietf.multi6 |
|---|---|
| Organization | IBM |
| Message-ID | <[email protected]> |
Erik Nordmark wrote:
...
>
>>I guess that different apps will have different security requirements.
>>However, i am considering the default scenario here. I mean the multi6
>>solution will provide some default level of security based on some
>>security tools used by the solution.
>>If a particular communication requires additional security, it will
>>obtain it by special means (TLS for instance)
>
>
> But TLS wouldn't by itself prevent a weakness in the multihoming layer
> being used to redirect the packets to a black hole; neither would IPsec
> when IPsec is layer above the multihoming layer.
Yes, let's focus on multi6 not making things worse at the network
layer, now that we have decided to focus on network layer solutions.
As long as we meet that goal, and allow IPSEC and TLS to work as
normal, we haven't made things worse for apps, and that all we
should aim at.
Brian