RE: RDDP WG Seoul minutes

[email protected]
Newsgroups gmane.ietf.rddp
Message-ID <[email protected]>
John,

> There also was a discussion about the additional touching/moving of data
> that would be required for things like RPCSEC_GSS security.  The
discussion
> focused around: if IPSec was used then the cryptographic/encryption action
> could be taken before the data was placed so that no additional
> touching/moving of the data would be needed after the data was delivered.
> Since the elimination of the extra movement/touching is the major focus
> of RDMA, it maybe seen as a sever reduction in the promises of RDMA to
> use anything other than IPSec to secure an interaction.

The minutes have been submitted.  That discussion was a bit on the
inconclusive side, in part because NFSv4 now has an RPCSEC_GSS mode
that assumes use of IPsec and hence does not secure the transmitted
data.  IMHO, the stronger case for IPsec over RPCSEC_GSS is that the
former can protect the RDDP headers (DDP, RDMAC), whereas the latter
cannot (assuming that we rule out some ugly passing of security info
from NFS down to RDDP).  Let me know if you want me to try to edit/change
the submitted minutes.

> Anyway, this was also one of the conversation threads that we talked
> about bringing to the list for additional discussion.

That will happen in the context of the IPsec requirements issue [(4) in
the minutes] that will be coming to the list ... although I'd like to try
to close out a few of the other issues before opening that Pandora's box ...

Thanks,
--David

-----Original Message-----
From: John Hufferd [mailto:[email protected]] 
Sent: Sunday, March 28, 2004 3:46 PM
To: [email protected]
Cc: [email protected]
Subject: Re: [rddp] RDDP WG Seoul minutes



David, 
In addition to the information you stated below: 

 Section 9 - Should we require IPsec, and therefore implement 
 this section, or make it optional? Suggestion that it be made 
 "mandatory-to-implement, optional-to-use." It was observed that 
 IPS had a similar section because it needed it. Also, now that 
 there is the IKEv2 specification to refer to, the problem is no longer 
 so difficult to document.  Look at IKEv2 and new "Cryptographic
 Algorithms for IKEv2" draft.  If these are used this section in
 the RDDP security draft may not be necessary, as an IKEv2
 reference will be adequate. 

 (4) Core question: Should we say that IPsec is mandatory for RDDP? 
 Secondary question: What parts do we actually require? (IKEv2?) 
 Take to list! Also, take to NFSv4 WG the next day. (NFS has no 
 such requirement currently, and has its own RPCSEC_GSS security 
 support). 

 The mandatory security item generated significant discussion but was 
 highly inconclusive. It was observed that mandatory-to-implement 
 would be a significant enhancement to the review approval process. 

There also was a discussion about the additional touching/moving of data
that would be required for things like RPCSEC_GSS security.  The discussion
focused around: if IPSec was used then the cryptographic/encryption action
could be taken before the data was placed so that no additional
touching/moving of the data would be needed after the data was delivered.
Since the elimination of the extra movement/touching is the major focus of
RDMA, it maybe seen as a sever reduction in the promises of RDMA to use
anything other than IPSec to secure an interaction. 

Anyway, this was also one of the conversation threads that we talked about
bringing to the list for additional discussion. 

.
.
John L. Hufferd
Senior Technical Staff Member (STSM)
IBM/System Group, San Jose CA
Main Office: (408) 256-0403, Tie: 276-0403, eFax: (408) 904-4688
Alt Office: (408) 997-6136, Cell: (408) 499-9702
Internet Address: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.