Re: rework IPsec intro
Michael Richardson <[email protected]>
| Newsgroups | gmane.os.netbsd.devel.network |
|---|---|
| Message-ID | <[email protected]> |
Andrew Cagney <[email protected]> wrote: >> Good work. Maybe, mention that AH is fundamentally incompatible with >> NAT44, and as a result, as had essentially zero deployment outside of >> limited domains. (see RFC8799) > Thanks for the addition, I'll add it. I was trying to be subtle and > only hint at AH being dead. Screw that :-) As an advocate for AH use, it died when we tried to use it 15 years ago in SEND (Securing Neighbor Discovery), but we couldn't, because we defined the behaviour of unknown-SPI wrong. For ESP, error. For AH, pretend there is no AH and keep going. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works | IoT architect [ ] [email protected] http://www.sandelman.ca/ | ruby on rails [