Re: Review of GIST over SCTP and DTLS - updated
Xiaoming Fu <[email protected]> Thu, 25 Mar 2010 19:00:43 -0700
| Newsgroups | gmane.ietf.nsis |
|---|---|
| Message-ID | <[email protected]> |
Hi Jukka, The GIST spec tells how one could "stack" a multitude of security and transport protocols as MA protocol IDs, via the "Stack-Proposal" and "Stack-Config-Data". To add: This has also been documented in the extensibility draft currently being IETF last call (which is good!). Xiaoming On 3/25/2010 6:29 PM, Jukka Manner wrote: > Hi Xiaoming, > > Maybe I'm not getting it, but how do you differentiate in the proposal > > 1. SCTP > 2. SCTP with DTLS security > 3. DCCP with DTLS security > > If DTLS is it's own MA ID, then you always need to specify in addition > which underlying transport is used with it? > > Jukka > > On 03/25/2010 05:24 PM, Xiaoming Fu wrote: >> Hi Jukka, >> >> Thanks a lot for your comments. >> >> We will address issues your raised and submit a new version asap, with a >> clarification to your last part comments: >> > - 9. IANA section: name the MA protocol 4 differently, we could also >> > have DCCP and DTLS. Thus, MA protocol 4 is DTLS over SCTP." >> nsis/current/msg08493.html >> http://www.ietf.org/mail-archive/web >> Earlier the WG has commented on this, and seems to have agreed on >> identifying DTLS as a separate MA (thus the ID changed its name as >> well), which can be used for SCTP and other transport mechanisms in the >> future: >> >> http://www.ietf.org/mail-archive/web//nsis/current/msg08483.html >> >> I think this way might make more sense, as it allows a stacked MAs >> (alike TLS vs TCP). >> What do you think? >> Xiaoming >> On 3/25/2010 5:00 PM, Jukka Manner wrote: >>> Hi Xiaoming, >>> >>> I have reviewed the draft and would like to see the following things >>> fixed before we can conclude that the draft is ready to go forward: >>> >>> - Introduction: >>> * what are these "other issues" of TCP? Please clarify. >>> * "...especially if deployment over the public Internet is >>> contemplated": I don't quite get this statement. SCTP, as DCCP, does not >>> natively get through firewalls (nor NATs), so SCTP is not directly >>> applicable to the Internet at large, on the contrary. >>> >>> - S3.4: s/"was able to remain"/"was able to retain"/ >>> >>> - 5.1: In practice the multihoming support of SCTP is not that >>> beneficial. Since NSIS is about signaling on the data path, and if that >>> data path fails, it doesn't really the application if the state can >>> still be refreshed using an alternative path. The only benefit of >>> multihoming might be that the state on the failed path can be more >>> quickly torn down using the multihoming capability of SCTP. So, please >>> be more clear on this, the current text goes back and forth on the >>> topic. >>> >>> - 9. IANA section: name the MA protocol 4 differently, we could also >>> have DCCP and DTLS. Thus, MA protocol 4 is DTLS over SCTP. >>> >>> Regards, >>> Jukka > -- Xiaoming Fu, http://user.informatik.uni-goettingen.de/~fu