Two security issues from IETF #57

[email protected]
Newsgroups gmane.ietf.rserpool
Message-ID <57A26D272F67A743952F6B4371B8F811021CFE4C@daebe007.americas.nokia.com>
The security discussion at IETF #57 raised two issues that we agreed would be brought to the list for comment.

Issue #1
TLS or IPsec mandatory to implement?

The security design team consensus was that the network designer could either use TLS or IPsec as mandatory to implement for ENRP-PE and ENRP-ENRP communication.  The PU-ENRP was previously decided to be mandatory to implement TLS for reasons of interoperability.    Direction from the ADs and consensus in the meeting was that one security mechanism should be made mandatory to implement for all.  It was agreed to select TLS as mandatory to implement by those attending the meeting.  Do the people on the list agree?

Issue #2
Security of ENRP server registrations and ENRP to ENRP communications

Other clarifications included the restriction of pool elements within a particular pool to provide the same level of security, for simplicity.  In addition, an ENRP server will either have all registrations and thus namespace entries secured or none, also for reasons of simplicity.  A mixed security rating for the elements stored in the ENRP database would complicate the client as well as the ENRP server.   The client would have to implement a security policy which would review the entries returned by ENRP and select them based on a security policy.  It is also unclear what the impact of a mixed database is on security as a whole.  It was agreed to restrict the ENRP database to secure registrations only and secure communications between ENRP servers OR insecure registrations only by those attending the meeting.  Do the people on the list agree?

Comments?

-- maureen
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.