AD comments on draft-ietf-rohc-ipsec-extensions-hcoipsec-04
Magnus Westerlund <[email protected]> Thu, 14 May 2009 18:09:00 +0200
| Newsgroups | gmane.ietf.rohc |
|---|---|
| Message-ID | <[email protected]> |
Hi
My comments on the IPsec extensions.
Section 3.1:
Shouldn't it be discussed when this protocol number is appropriate to be
used. To me it appears that some requirements need to be fulfilled
before one uses it on a particular layer. Running ROHC straight on top
of IPv6 for example seems like a bad idea in most case due to such
considerations as security and denial of service for the decompressor,
the multi-hop environment, and lack of clear logical channel.
Section 3.2.1:
I think the language in this section could be benefit from being written
in active tense saying what to do, rather than what happens. Especially
when we comes to bullets like:
The decompressed packet is used with the integrity algorithm (and
its respective key) to compute a ROHC ICV that is compared to the
appended ICV (if these two values differ, the packet is dropped)
The second parenthesis seems to be a very hard requirement because
otherwise the ROHCoIPsec solution doesn't have a clear integrity
preserving property.
Section 3.2.1:
What ICV algorithms and key lengths must be supported in the
implementations? This is to ensure that there are at least one algorithm
and key length that are supported by everyone.
Cheers
Magnus Westerlund
IETF Transport Area Director & TSVWG Chair
----------------------------------------------------------------------
Multimedia Technologies, Ericsson Research EAB/TVM
----------------------------------------------------------------------
Ericsson AB | Phone +46 10 7148287
Färögatan 6 | Mobile +46 73 0949079
SE-164 80 Stockholm, Sweden| mailto: [email protected]
----------------------------------------------------------------------