Why IPsec is needed for iSCSI but might not be needed for RDDP/iWARP
John Hufferd <[email protected]>
| Newsgroups | gmane.ietf.rddp |
|---|---|
| Message-ID | <OF2F73D453.AAEF1574-ON88256EAD.0064E71F-88256EAD.0067D853@us.ibm.com> |
David, Perhaps you could explain again for me and perhaps some other "dense" folks why IPsec would be a MUST implement (but optional to use) for iSCSI but we are attempting to not say similar things for RDMA/iWARP. I am not pushing an agenda here, I know that if we do not need IPsec for RDMA/iWARP on clusters and other such reasonably secure environments, the requirements of IPsec as a MUST implement in all cases will NOT be approprate. (And often the RNIC used for such clustering environment is on its own Subnet and not part of a general communication network.) But I also feel that when RNICs are used on less secure environments, that the environment looks similar to iSCSI. Perhaps even less secure because of the RNIC holding the placement open to a storage location were with HW iSCSI, the direct placement and the protocol are closely combined so that Buffers are not left open for the intruder (at least not as much). So based on the above thoughts, I am not sure why it was required for iSCSI to use IPsec (when iSCSI HW is more secure than RNICs) and not an issue for RDMA/iWARP. I get (but do not buy) the arguments that RDMA/iWARP is just using the TCP/IP (or SCTP) and as such does not need any other protection that is given to that, but then so was iSCSI. So your thoughts about why it would be needed in one and not the other would be of interest. Since I do not see that a solution for protecting the Buffers (single shot or what ever) changes the issue of why iSCSI and not RDMA/iWARP. If we protect the Buffers, then the results will have a similar profile to iSCSI. So that alone can not be a full solution. If your position is that it is needed for both regardless of the buffer protection, and you are suggesting that we might come up with something that handles "authentication" at the DDP layer via Cryptographic approaches as a possible approach to meeting the need, then I can understand the logic as far as it goes. But you have not said anything about the need for Privacy (Encryption). I thought that was also an important consideration. Anyway, perhaps you could address the above, and help clarify the issues for some of us. Also as a second point, does it make since to attempt to define environments where RDMA/iWARP would be approprate without the additional Cryptographic or IPsec implementations (such as within clusters on their own physical subnets, etc.), and then require IPsec in other less secure environments? . . John L. Hufferd Senior Technical Staff Member (STSM) IBM/System Group, San Jose CA Main Office: (408) 256-0403, Tie: 276-0403, eFax: (408) 904-4688 Alt Office: (408) 997-6136, Cell: (408) 499-9702 Internet Address: [email protected] _______________________________________________ rddp mailing list [email protected] https://www1.ietf.org/mailman/listinfo/rddp