Re: IPsec and RDDP as a transport

John Hufferd <[email protected]>
Newsgroups gmane.ietf.rddp
Message-ID <OFA62706EF.478E77E4-ON88256EA1.0029416E-88256EA1.002A55BA@us.ibm.com>
I believe there will be many applications that will use STags for more 
than one shot, and the RNIC vendors must be set up to permit more then 
single shot.  An example of this use is in storage where the storage 
controller needs to pace its data movement from the initiator, in sizes 
that match the available cache space at any given moment.  The I/O command 
however would only advertize a singe STag for such an implementation.  I 
am sure there may be many applications like that.  So the point is we can 
not restrict it to just single shot.  And if we ever want to have 
compatibility between InfiniBand and iWARP, we need to have multi-shot 
STags.

I do not think we should encourage the lack of compatibility nor should we 
do anything that prevents the use of the RDMA technology with Storage and 
other such applications.


.
.
John L. Hufferd
Senior Technical Staff Member (STSM)
IBM/System Group, San Jose CA




[email protected] 
Sent by: [email protected]
05/26/2004 08:52 PM

To
[email protected]
cc

Subject
[rddp] IPsec and RDDP as a transport






I think the discussion with Caitlin has reached the point
where a summary and opening up the discussion to others is
in order.

In essence, Caitlin strongly suggests that RDDP's security
requirements should be derived by considering it as a transport
protocol optimization and looking to what is required of other
transport protocols.  SCTP (RFC 2960) is an obvious place to
look.

I think that this is viable (although I'm probably in for a
lengthy discussion with the security ADs - part of my job
as a WG chair), but there are three important consequences
that I'd like to see comments on:

(1) The "no IPsec" (or equivalent mechanism) level of requirement
                 would apply only to implementations that restrict all 
STags
                 to be one-shot (single use in some sense).

(2) Implementations that allow longer-lived STags would in all
                 likelihood be subject to a stronger security requirement
                 due to the increased application exposure created by
                 long-lived STags.

(3) STag values will probably have a randomness requirement to
                 make them hard to guess.  See the discussion of the SCTP
                 Initiate Tag and its randomness requirements in RFC 2960
                 (e.g., Section 5.3.1).

Thanks,
--David
----------------------------------------------------
David L. Black, Senior Technologist
EMC Corporation, 176 South St., Hopkinton, MA  01748
+1 (508) 293-7953             FAX: +1 (508) 293-7786
[email protected]        Mobile: +1 (978) 394-7754
----------------------------------------------------

_______________________________________________
rddp mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/rddp

_______________________________________________
rddp mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/rddp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.