Re: Security scenarios and basic functions
"Baoqing Ye" <[email protected]>
| Newsgroups | gmane.ietf.rmt |
|---|---|
| Message-ID | <[email protected]> |
my 2 cents: On 6/30/06, Rex Buddenberg <[email protected]> wrote: > > On Fri, 2006-06-30 at 07:11 -0400, George Gross wrote: > > > 3. Confidentiality, i.e. the possibility to prevent someone not > > > authorized to see what is transported within the protocol, and in some > > > case even seeing what is happening within the protocol itself. > > -- I'd suggest to leave confidentiality as optional, or at least to be really careful about the algorithms to be proposed, considering the overhead the encryption of all payload it brings to the picture which will inevitably reduce overall performance (significantly). IPsec is not a complete solution. It applies to layer 3 which means you > are protecting infrastructure ... only indirectly protecting the data. > The practical implication is that you have technician-based insiders in > the enclaves. (I've no objection whatever to reusing IPsec building > blocks at layers 4 and 7). -- I agree with the statement above. I also wonder if there has been any analysis work done from performance perspective for layer 3 solution v.s. layer 4/7 solutions. -Baoqing Ye- Verizon Lab, LAOMS59, 40 Sylvan Road, Waltham, MA 02451, USA _______________________________________________ Rmt mailing list [email protected] https://www1.ietf.org/mailman/listinfo/rmt