Re: RDDP WG Seoul minutes
John Hufferd <[email protected]>
| Newsgroups | gmane.ietf.rddp |
|---|---|
| Message-ID | <OF65689339.EAB9940E-ON08256E65.00707353-08256E65.00720EB1@us.ibm.com> |
David, In addition to the information you stated below: Section 9 - Should we require IPsec, and therefore implement this section, or make it optional? Suggestion that it be made "mandatory-to-implement, optional-to-use." It was observed that IPS had a similar section because it needed it. Also, now that there is the IKEv2 specification to refer to, the problem is no longer so difficult to document. Look at IKEv2 and new "Cryptographic Algorithms for IKEv2" draft. If these are used this section in the RDDP security draft may not be necessary, as an IKEv2 reference will be adequate. (4) Core question: Should we say that IPsec is mandatory for RDDP? Secondary question: What parts do we actually require? (IKEv2?) Take to list! Also, take to NFSv4 WG the next day. (NFS has no such requirement currently, and has its own RPCSEC_GSS security support). The mandatory security item generated significant discussion but was highly inconclusive. It was observed that mandatory-to-implement would be a significant enhancement to the review approval process. There also was a discussion about the additional touching/moving of data that would be required for things like RPCSEC_GSS security. The discussion focused around: if IPSec was used then the cryptographic/encryption action could be taken before the data was placed so that no additional touching/moving of the data would be needed after the data was delivered. Since the elimination of the extra movement/touching is the major focus of RDMA, it maybe seen as a sever reduction in the promises of RDMA to use anything other than IPSec to secure an interaction. Anyway, this was also one of the conversation threads that we talked about bringing to the list for additional discussion. . . John L. Hufferd Senior Technical Staff Member (STSM) IBM/System Group, San Jose CA Main Office: (408) 256-0403, Tie: 276-0403, eFax: (408) 904-4688 Alt Office: (408) 997-6136, Cell: (408) 499-9702 Internet Address: [email protected]