Re: [MEXT] Call for WG adoption of I-D: draft-korhonen-mext-mip6-altsec
Julien Laganier <[email protected]>
| Newsgroups | gmane.ietf.nemo |
|---|---|
| Message-ID | <[email protected]> |
Jouni, > Jouni wrote: >> >> Hmm.. we do handle SPIs differently and our "ESP" can be absent even if >> UDP encap is used. Would that be an issue regarding the reuse of >> existing formats? The issue with reusing of the ESP syntax outside ESP is that it is duplication of the same protocol functionality which goes against one of the Architectural Principles of the Internet again: "If a previous design, in the Internet context or elsewhere, has successfully solved the same problem, choose the same solution unless there is a good technical reason not to. Duplication of the same protocol functionality should be avoided as far as possible, without of course using this argument to reject improvements.choose the same solution unless there is a good technical reason not to" So what is your good technical reason not to reuse IPsec ESP and simply provide an underlying UDP encapsulation? Also -- turning my earlier statements into questions in case it wasn't clear I was expecting clarifications / answers : On Fri, Jan 28, 2011 at 3:10 PM, Laganier, Julien <[email protected]> wrote: > None of these two points explains to me why you have to duplicate ESP functionality: > > 1) You have chosen to handle SPI differently, but I don't know why. So, why? > 2) As to ESP being absent, if the goal is to not protect some of the user-plane traffic, > you can use ESP-NULL, or just the UDP encap... So why wouldn't that be sufficient? --julien