1 Aug 2003 16:29
Re: revised IPsec processing model
Mark Duffy <mduffy <at> quarrytech.com>
2003-08-01 14:29:31 GMT
2003-08-01 14:29:31 GMT
At 03:22 PM 7/31/2003 -0400, Stephen Kent wrote: >Mark, > >I've trimmed the message to keep it readable, since I think we agree on >the facts, just not what to do as a result(Continue reading). > >So we agree that there is a way to achieve source-based SPD selection, and >to provide independent forwarding, but you don't think the mechanism is >not elegant. Well of course a device can select an SPD in any way it wants; the issue here is about whether the IPsec standard sanctions it or not. With the proposed model of 2401bis it might be debatable whether certain behaviors comply, as it would depend on how liberal one is in defining "interface" and "forwarding function". If 2401bis makes it clear that these terms may be widely construed, then I agree that the proposed model is flexible enough at least for the devices I am envisioning. > If I understand your suggestion, though, you would remove all > specification of this functionality, and I don't think we have a useful > spec if we do that. Did I misunderstand what you were suggesting here? I think maybe you did. My suggestion in a nutshell is not to remove specification but to modify it thus: 1. Say that the SPD is selected by an "SPD selection function" rather than by a "forwarding function". If we are considering that the "forwarding function" may be arbitrary anyway, this wording change seems to me to be no more than being honest with ourselves.
.
>
>So we agree that there is a way to achieve source-based SPD selection, and
>to provide independent forwarding, but you don't think the mechanism is
>not elegant.
Well of course a device can select an SPD in any way it wants; the issue
here is about whether the IPsec standard sanctions it or not. With the
proposed model of 2401bis it might be debatable whether certain behaviors
comply, as it would depend on how liberal one is in defining "interface"
and "forwarding function". If 2401bis makes it clear that these terms may
be widely construed, then I agree that the proposed model is flexible
enough at least for the devices I am envisioning.
> If I understand your suggestion, though, you would remove all
> specification of this functionality, and I don't think we have a useful
> spec if we do that. Did I misunderstand what you were suggesting here?
I think maybe you did. My suggestion in a nutshell is not to remove
specification but to modify it thus:
1. Say that the SPD is selected by an "SPD selection function" rather
than by a "forwarding function". If we are considering that the
"forwarding function" may be arbitrary anyway, this wording change seems to
me to be no more than being honest with ourselves.
RSS Feed