Re: [anonsec] I-D Action:draft-ietf-btns-connection-latching-06.txt

Nicolas Williams <Nicolas.Williams@sun.com> Mon, 07 April 2008 19:53 UTC

Return-Path: <anonsec-bounces@postel.org>
X-Original-To: ietfarch-btns-archive-waDah9Oh@core3.amsl.com
Delivered-To: ietfarch-btns-archive-waDah9Oh@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id BE2F63A6D2C for <ietfarch-btns-archive-waDah9Oh@core3.amsl.com>; Mon, 7 Apr 2008 12:53:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.717
X-Spam-Level:
X-Spam-Status: No, score=-0.717 tagged_above=-999 required=5 tests=[AWL=-2.266, BAYES_00=-2.599, SARE_GIF_ATTACH=1.42, SB_GIF_AND_NO_URIS=2.728]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8v0bqkUt7013 for <ietfarch-btns-archive-waDah9Oh@core3.amsl.com>; Mon, 7 Apr 2008 12:53:42 -0700 (PDT)
Received: from boreas.isi.edu (boreas.isi.edu [128.9.160.161]) by core3.amsl.com (Postfix) with ESMTP id E884C3A6C03 for <btns-archive-waDah9Oh@lists.ietf.org>; Mon, 7 Apr 2008 12:53:42 -0700 (PDT)
Received: from boreas.isi.edu (localhost [127.0.0.1]) by boreas.isi.edu (8.13.8/8.13.8) with ESMTP id m37Jfgaa001363; Mon, 7 Apr 2008 12:41:42 -0700 (PDT)
Received: from brmea-mail-1.sun.com (brmea-mail-1.Sun.COM [192.18.98.31]) by boreas.isi.edu (8.13.8/8.13.8) with ESMTP id m37JcCit029413 for <anonsec@postel.org>; Mon, 7 Apr 2008 12:38:13 -0700 (PDT)
Received: from dm-central-01.central.sun.com ([129.147.62.4]) by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m37JcCXg019305 for <anonsec@postel.org>; Mon, 7 Apr 2008 19:38:12 GMT
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104]) by dm-central-01.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL, v2.2) with ESMTP id m37JcBFs039982 for <anonsec@postel.org>; Mon, 7 Apr 2008 13:38:11 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1]) by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m37JcB6O005119; Mon, 7 Apr 2008 14:38:11 -0500 (CDT)
Received: (from nw141292@localhost) by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m37JcB9v005118; Mon, 7 Apr 2008 14:38:11 -0500 (CDT)
X-Authentication-Warning: binky.Central.Sun.COM: nw141292 set sender to Nicolas.Williams@sun.com using -f
Date: Mon, 7 Apr 2008 14:38:11 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Daniel Migault <mglt.biz@gmail.com>, anonsec@postel.org
Message-ID: <20080407193811.GK16998@Sun.COM>
Mail-Followup-To: Daniel Migault <mglt.biz@gmail.com>, anonsec@postel.org
References: <20080225093002.01ABB3A6CB2@core3.amsl.com> <c17ec2f80803132253k6442ec40m99be1872704f5c5a@mail.gmail.com> <20080407180003.GB16998@Sun.COM>
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="VkVuOCYP9O7H3CXI"
Content-Disposition: inline
In-Reply-To: <20080407180003.GB16998@Sun.COM>
User-Agent: Mutt/1.5.7i
X-ISI-4-43-8-MailScanner: Found to be clean
X-MailScanner-From: nicolas.williams@sun.com
Subject: Re: [anonsec] I-D Action:draft-ietf-btns-connection-latching-06.txt
X-BeenThere: anonsec@postel.org
X-Mailman-Version: 2.1.6
Precedence: list
List-Id: "Discussions of anonymous Internet security." <anonsec.postel.org>
List-Unsubscribe: <http://mailman.postel.org/mailman/listinfo/anonsec>, <mailto:anonsec-request@postel.org?subject=unsubscribe>
List-Archive: <http://mailman.postel.org/pipermail/anonsec>
List-Post: <mailto:anonsec@postel.org>
List-Help: <mailto:anonsec-request@postel.org?subject=help>
List-Subscribe: <http://mailman.postel.org/mailman/listinfo/anonsec>, <mailto:anonsec-request@postel.org?subject=subscribe>
Sender: anonsec-bounces@postel.org
Errors-To: anonsec-bounces@postel.org

On Mon, Apr 07, 2008 at 01:00:04PM -0500, Nicolas Williams wrote:
> On Fri, Mar 14, 2008 at 06:53:24AM +0100, Daniel Migault wrote:
> > < The considered model can be thus represented by the figure below:
> 
> I like your ASCII art, but I'm going to modify it somewhat.

How about this (GIF version attached):

   +--------------------------------------------+
   |                       +--------------+     |
   |                       |Administrator |     |
   |                       |apps          |     |
   |                       +--------------+     |
   |                              ^             |
   |                              |             | user mode
   |                              v             |
   | +--------------+      +---------------+    |
   | |App           |      |IKEv2          |    |
   | |              |      | +---+  +----+ |    |
   | |              |      | |PAD|  |SPD | |    |
   | |              |      | +---+  +--^-+ |    |
   | +--------------+      +-----------|---+    |
   |   ^                               |        |
   +---|-------------------------------|--------+  user/kernel mode
   +---|-------------------------------|--------+  interface
   |   v                               |        |
   |+-------+   +----------------------|-------+|
   ||ULP    |   | IPsec key manager    |       ||
   |+-------+   |               +------v------+||
   | ^  ^       |               | Logical SPD |||
   | |  |       |               +-----------^-+||
   | |  |       | +----------+    +-----+   |  ||  kernel mode
   | |  +-------->| Latch DB |<-->| SAD |   |  ||
   | |          | +----------+    +--^--+   |  ||
   | |          +--------------------|------|--+|
   +-|-------------------------------v------v---+
   | | IPsec Layer  (ESP/AH)                    |
   | |                                          |
   +-v------------------------------------------+
   |   IP Layer                                 |
   +--------------------------------------------+
_______________________________________________