| Newsgroups |
gmane.ietf.rddp |
| Message-ID |
<[email protected]> |
John,
> There also was a discussion about the additional touching/moving of data
> that would be required for things like RPCSEC_GSS security. The
discussion
> focused around: if IPSec was used then the cryptographic/encryption action
> could be taken before the data was placed so that no additional
> touching/moving of the data would be needed after the data was delivered.
> Since the elimination of the extra movement/touching is the major focus
> of RDMA, it maybe seen as a sever reduction in the promises of RDMA to
> use anything other than IPSec to secure an interaction.
The minutes have been submitted. That discussion was a bit on the
inconclusive side, in part because NFSv4 now has an RPCSEC_GSS mode
that assumes use of IPsec and hence does not secure the transmitted
data. IMHO, the stronger case for IPsec over RPCSEC_GSS is that the
former can protect the RDDP headers (DDP, RDMAC), whereas the latter
cannot (assuming that we rule out some ugly passing of security info
from NFS down to RDDP). Let me know if you want me to try to edit/change
the submitted minutes.
> Anyway, this was also one of the conversation threads that we talked
> about bringing to the list for additional discussion.
That will happen in the context of the IPsec requirements issue [(4) in
the minutes] that will be coming to the list ... although I'd like to try
to close out a few of the other issues before opening that Pandora's box ...
Thanks,
--David
-----Original Message-----
From: John Hufferd [mailto:[email protected]]
Sent: Sunday, March 28, 2004 3:46 PM
To: [email protected]
Cc: [email protected]
Subject: Re: [rddp] RDDP WG Seoul minutes
David,
In addition to the information you stated below:
Section 9 - Should we require IPsec, and therefore implement
this section, or make it optional? Suggestion that it be made
"mandatory-to-implement, optional-to-use." It was observed that
IPS had a similar section because it needed it. Also, now that
there is the IKEv2 specification to refer to, the problem is no longer
so difficult to document. Look at IKEv2 and new "Cryptographic
Algorithms for IKEv2" draft. If these are used this section in
the RDDP security draft may not be necessary, as an IKEv2
reference will be adequate.
(4) Core question: Should we say that IPsec is mandatory for RDDP?
Secondary question: What parts do we actually require? (IKEv2?)
Take to list! Also, take to NFSv4 WG the next day. (NFS has no
such requirement currently, and has its own RPCSEC_GSS security
support).
The mandatory security item generated significant discussion but was
highly inconclusive. It was observed that mandatory-to-implement
would be a significant enhancement to the review approval process.
There also was a discussion about the additional touching/moving of data
that would be required for things like RPCSEC_GSS security. The discussion
focused around: if IPSec was used then the cryptographic/encryption action
could be taken before the data was placed so that no additional
touching/moving of the data would be needed after the data was delivered.
Since the elimination of the extra movement/touching is the major focus of
RDMA, it maybe seen as a sever reduction in the promises of RDMA to use
anything other than IPSec to secure an interaction.
Anyway, this was also one of the conversation threads that we talked about
bringing to the list for additional discussion.
.
.
John L. Hufferd
Senior Technical Staff Member (STSM)
IBM/System Group, San Jose CA
Main Office: (408) 256-0403, Tie: 276-0403, eFax: (408) 904-4688
Alt Office: (408) 997-6136, Cell: (408) 499-9702
Internet Address: [email protected]