Re: [Hipsec] BEET discussions

Pekka Nikander <pekka.nikander@nomadiclab.com> Tue, 25 November 2008 15:48 UTC

Return-Path: <hipsec-bounces@ietf.org>
X-Original-To: hip-archive@lists.ietf.org
Delivered-To: ietfarch-hip-archive@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 178683A6BFC; Tue, 25 Nov 2008 07:48:17 -0800 (PST)
X-Original-To: hipsec@core3.amsl.com
Delivered-To: hipsec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 1990D3A6BFC for <hipsec@core3.amsl.com>; Tue, 25 Nov 2008 07:48:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bq8PePZDVCcg for <hipsec@core3.amsl.com>; Tue, 25 Nov 2008 07:48:15 -0800 (PST)
Received: from n2.nomadiclab.com (n2.nomadiclab.com [IPv6:2001:14b8:400:101::2]) by core3.amsl.com (Postfix) with ESMTP id 046DA3A6BFB for <hipsec@ietf.org>; Tue, 25 Nov 2008 07:48:15 -0800 (PST)
Received: from n2.nomadiclab.com (localhost [127.0.0.1]) by n2.nomadiclab.com (Postfix) with ESMTP id C24D11EF8B6; Tue, 25 Nov 2008 17:48:11 +0200 (EET)
Received: from [127.0.0.1] (localhost [IPv6:::1]) by n2.nomadiclab.com (Postfix) with ESMTP id 4FAF31EF8B5; Tue, 25 Nov 2008 17:48:11 +0200 (EET)
Message-Id: <2F7887B7-4121-4DD0-B7DC-6E595DA486EE@nomadiclab.com>
From: Pekka Nikander <pekka.nikander@nomadiclab.com>
To: Robert Moskowitz <rgm@htt-consult.com>
In-Reply-To: <492C1907.1040908@htt-consult.com>
Mime-Version: 1.0 (Apple Message framework v929.2)
Date: Tue, 25 Nov 2008 17:48:11 +0200
References: <492C1907.1040908@htt-consult.com>
X-Mailer: Apple Mail (2.929.2)
X-Virus-Scanned: ClamAV using ClamSMTP
Cc: HIP <hipsec@ietf.org>
Subject: Re: [Hipsec] BEET discussions
X-BeenThere: hipsec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "This is the official IETF Mailing List for the HIP Working Group." <hipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/hipsec>, <mailto:hipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/pipermail/hipsec>
List-Post: <mailto:hipsec@ietf.org>
List-Help: <mailto:hipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hipsec>, <mailto:hipsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="us-ascii"; Format="flowed"; DelSp="yes"
Sender: hipsec-bounces@ietf.org
Errors-To: hipsec-bounces@ietf.org

BEET mode was discussed in its early dais, and was basically rejected  
by the IPsec folks (mainly Steve K) then, mainly due to not being any  
"need" for it, or just not wanting even to consider a new mode to  
IPsec.  Then some people claimed that it would be better to simply  
used inner header compression instead.

--Pekka

On 25 Nov 2008, at 17:25, Robert Moskowitz wrote:

> Has BEET mode been discussed outside of the HIP list?
>
> In my work last week to get HIP moving to Standards track, it became  
> clear that BEET ESP will be a part of this and it will need to be  
> reviewed by IPsec-centric people.  Tim Polk already had Sheila  
> Frankel looking at it, and Paul Hoffman acknowledged that he would  
> also have to review it.
>
> One thing that became evident is that the why of BEET mode is needed  
> to be clearly stated.  For example I am missing the explaination  
> that in BEET mode, the SA survives changes to the outer IP addresses.
>
> Also the semantics are related to tunnel mode with a nod to tranport  
> mode.
>
> I am still trying to get a feel for the ID.  It still feels like the  
> placement of BEET mode with respect to the other modes is defused  
> over the document and not well delineated in the beginning.  Not  
> only what BEET adds, but what problems occur when you try to do BEET  
> semantics with tunnel or transport instead.
>
> I do want to say that I applaud the efforts that went into creating  
> BEET mode, developing the current draft, and getting it into the  
> 2.6.27 kernel (of course I want it in the 2.6.18 kernel as well  
> without patching....).
>
>
> _______________________________________________
> Hipsec mailing list
> Hipsec@ietf.org
> https://www.ietf.org/mailman/listinfo/hipsec
>

_______________________________________________
Hipsec mailing list
Hipsec@ietf.org
https://www.ietf.org/mailman/listinfo/hipsec