Re: Review of GIST over SCTP and DTLS - updated

Xiaoming Fu <[email protected]> Thu, 25 Mar 2010 19:00:43 -0700
Newsgroups gmane.ietf.nsis
Message-ID <[email protected]>
Hi Jukka,

The GIST spec tells how one could "stack" a multitude of security and 
transport protocols as MA protocol IDs, via the "Stack-Proposal" and 
"Stack-Config-Data".

To add: This has also been documented in the extensibility draft 
currently being IETF last call (which is good!).

Xiaoming
On 3/25/2010 6:29 PM, Jukka Manner wrote:
> Hi Xiaoming,
>
> Maybe I'm not getting it, but how do you differentiate in the proposal
>
> 1. SCTP
> 2. SCTP with DTLS security
> 3. DCCP with DTLS security
>
> If DTLS is it's own MA ID, then you always need to specify in addition
> which underlying transport is used with it?
>
> Jukka
>
> On 03/25/2010 05:24 PM, Xiaoming Fu wrote:
>> Hi Jukka,
>>
>> Thanks a lot for your comments.
>>
>> We will address issues your raised and submit a new version asap, with a
>> clarification to your last part comments:
>> > - 9. IANA section: name the MA protocol 4 differently, we could also
>> > have DCCP and DTLS. Thus, MA protocol 4 is DTLS over SCTP."
>> nsis/current/msg08493.html
>> http://www.ietf.org/mail-archive/web
>> Earlier the WG has commented on this, and seems to have agreed on
>> identifying DTLS as a separate MA (thus the ID changed its name as
>> well), which can be used for SCTP and other transport mechanisms in the
>> future:
>>
>> http://www.ietf.org/mail-archive/web//nsis/current/msg08483.html
>>
>> I think this way might make more sense, as it allows a stacked MAs
>> (alike TLS vs TCP).
>> What do you think?
>> Xiaoming
>> On 3/25/2010 5:00 PM, Jukka Manner wrote:
>>> Hi Xiaoming,
>>>
>>> I have reviewed the draft and would like to see the following things
>>> fixed before we can conclude that the draft is ready to go forward:
>>>
>>> - Introduction:
>>> * what are these "other issues" of TCP? Please clarify.
>>> * "...especially if deployment over the public Internet is
>>> contemplated": I don't quite get this statement. SCTP, as DCCP, does not
>>> natively get through firewalls (nor NATs), so SCTP is not directly
>>> applicable to the Internet at large, on the contrary.
>>>
>>> - S3.4: s/"was able to remain"/"was able to retain"/
>>>
>>> - 5.1: In practice the multihoming support of SCTP is not that
>>> beneficial. Since NSIS is about signaling on the data path, and if that
>>> data path fails, it doesn't really the application if the state can
>>> still be refreshed using an alternative path. The only benefit of
>>> multihoming might be that the state on the failed path can be more
>>> quickly torn down using the multihoming capability of SCTP. So, please
>>> be more clear on this, the current text goes back and forth on the
>>> topic.
>>>
>>> - 9. IANA section: name the MA protocol 4 differently, we could also
>>> have DCCP and DTLS. Thus, MA protocol 4 is DTLS over SCTP.
>>>
>>> Regards,
>>> Jukka
>

-- 
Xiaoming Fu, http://user.informatik.uni-goettingen.de/~fu