RDDP Mandatory Security (IPsec)

[email protected]
Newsgroups gmane.ietf.rddp
Message-ID <[email protected]>
This email is bringing the first major issue from San
Diego in hopes of confirming the conclusions reached
in the meeting.  The draft minutes say:

  The issue at hand has two parts:

  (1) Should IPsec be required or optional?

  Sense of room: it should be required, but without any
  restrictions on how it is implemented.

NB: The sense of "no restrictions" is with respect to native
vs. Bump-in-the-stack vs. Bump-in-the-wire.  See Section 3.3
of RFC 2401

  (2) Should the IPsec requirements be based on the existing
	RFCs (e.g., use IKEv1) or the new drafts coming from the
	ipsec WG (e.g., use IKEv2).

  Sense of room: Base them on the existing RFCs by referencing
	the IP Storage IPsec requirements in RFC 3723.

  Two UPDATEs from after the meeting:
  - Making IPsec required clears the IESG security issue
	blocking the rddp architecture draft.
  - Based on the saag meeting on Thursday, the IETF Security
	Area has no problem with mandating use of IKEv1 in a
	new RFC, even though IKEv2 will be an RFC in the near
	future.

This is an opportunity for anyone who objects to these
"sense of the room" conclusions to do so, but please read
the entire San Diego minutes on this topic before doing so.

Thanks,
--David

----------------------------------------------------
David L. Black, Senior Technologist
EMC Corporation, 176 South St., Hopkinton, MA  01748
+1 (508) 293-7953             FAX: +1 (508) 293-7786
[email protected]        Mobile: +1 (978) 394-7754
----------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.