1 Jun 2004 03:38
RE: IPsec and RDDP as a transport
<Black_David <at> emc.com>
2004-06-01 01:38:58 GMT
2004-06-01 01:38:58 GMT
> If one shot STags would have been an acceptable solution, > why wouldn't making one shot STags a "MUST implement" > be adequate? Because that would allow long-lived STags without requiring the countermeasures for the security exposures they create. [... snip ...] > I also repeat my objection to requiring that a cleanly layered > RDDP implementation solve problems on a lower layer. > This is *extremely* bad policy. The SCTP mapping in particular > is quite suitable for implementation *over* SCTP. That's fine - see below for an approach that solves RDDP's problems within the RDDP layer ... > The probable effect of forcing inclusion of IPsec in an RNIC [... snip ...] This is going off on an unproductive tangent. Please reread the following from my earlier post: Given the resistance to a "MUST implement IPsec" requirement, the only obvious remaining path forward is to design security mechanisms into the RDDP protocols (i.e., solve the security exposures created by RDDP headers with long-lived STags without resorting to IPsec). To a first approximation, the security mechanisms will have to be able to address the following:(Continue reading)
RSS Feed