| Newsgroups |
gmane.ietf.rddp |
| Message-ID |
<[email protected]> |
I think the discussion with Caitlin has reached the point
where a summary and opening up the discussion to others is
in order.
In essence, Caitlin strongly suggests that RDDP's security
requirements should be derived by considering it as a transport
protocol optimization and looking to what is required of other
transport protocols. SCTP (RFC 2960) is an obvious place to
look.
I think that this is viable (although I'm probably in for a
lengthy discussion with the security ADs - part of my job
as a WG chair), but there are three important consequences
that I'd like to see comments on:
(1) The "no IPsec" (or equivalent mechanism) level of requirement
would apply only to implementations that restrict all STags
to be one-shot (single use in some sense).
(2) Implementations that allow longer-lived STags would in all
likelihood be subject to a stronger security requirement
due to the increased application exposure created by
long-lived STags.
(3) STag values will probably have a randomness requirement to
make them hard to guess. See the discussion of the SCTP
Initiate Tag and its randomness requirements in RFC 2960
(e.g., Section 5.3.1).
Thanks,
--David
----------------------------------------------------
David L. Black, Senior Technologist
EMC Corporation, 176 South St., Hopkinton, MA 01748
+1 (508) 293-7953 FAX: +1 (508) 293-7786
[email protected] Mobile: +1 (978) 394-7754
----------------------------------------------------