Re: IPsec and RDDP as a transport
John Hufferd <[email protected]>
| Newsgroups | gmane.ietf.rddp |
|---|---|
| Message-ID | <OFA62706EF.478E77E4-ON88256EA1.0029416E-88256EA1.002A55BA@us.ibm.com> |
I believe there will be many applications that will use STags for more than one shot, and the RNIC vendors must be set up to permit more then single shot. An example of this use is in storage where the storage controller needs to pace its data movement from the initiator, in sizes that match the available cache space at any given moment. The I/O command however would only advertize a singe STag for such an implementation. I am sure there may be many applications like that. So the point is we can not restrict it to just single shot. And if we ever want to have compatibility between InfiniBand and iWARP, we need to have multi-shot STags. I do not think we should encourage the lack of compatibility nor should we do anything that prevents the use of the RDMA technology with Storage and other such applications. . . John L. Hufferd Senior Technical Staff Member (STSM) IBM/System Group, San Jose CA [email protected] Sent by: [email protected] 05/26/2004 08:52 PM To [email protected] cc Subject [rddp] IPsec and RDDP as a transport I think the discussion with Caitlin has reached the point where a summary and opening up the discussion to others is in order. In essence, Caitlin strongly suggests that RDDP's security requirements should be derived by considering it as a transport protocol optimization and looking to what is required of other transport protocols. SCTP (RFC 2960) is an obvious place to look. I think that this is viable (although I'm probably in for a lengthy discussion with the security ADs - part of my job as a WG chair), but there are three important consequences that I'd like to see comments on: (1) The "no IPsec" (or equivalent mechanism) level of requirement would apply only to implementations that restrict all STags to be one-shot (single use in some sense). (2) Implementations that allow longer-lived STags would in all likelihood be subject to a stronger security requirement due to the increased application exposure created by long-lived STags. (3) STag values will probably have a randomness requirement to make them hard to guess. See the discussion of the SCTP Initiate Tag and its randomness requirements in RFC 2960 (e.g., Section 5.3.1). Thanks, --David ---------------------------------------------------- David L. Black, Senior Technologist EMC Corporation, 176 South St., Hopkinton, MA 01748 +1 (508) 293-7953 FAX: +1 (508) 293-7786 [email protected] Mobile: +1 (978) 394-7754 ---------------------------------------------------- _______________________________________________ rddp mailing list [email protected] https://www1.ietf.org/mailman/listinfo/rddp _______________________________________________ rddp mailing list [email protected] https://www1.ietf.org/mailman/listinfo/rddp