Re: [IPsec] #117: Hash and URL interop

Yoav Nir <ynir@checkpoint.com> Wed, 25 November 2009 08:32 UTC

Return-Path: <ynir@checkpoint.com>
X-Original-To: ipsec@core3.amsl.com
Delivered-To: ipsec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 9E8CC3A67B0 for <ipsec@core3.amsl.com>; Wed, 25 Nov 2009 00:32:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.519
X-Spam-Level:
X-Spam-Status: No, score=-2.519 tagged_above=-999 required=5 tests=[AWL=0.081, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YrjRXxrFZ22d for <ipsec@core3.amsl.com>; Wed, 25 Nov 2009 00:32:28 -0800 (PST)
Received: from dlpdemo.checkpoint.com (dlpdemo.checkpoint.com [194.29.32.54]) by core3.amsl.com (Postfix) with ESMTP id 347073A6A01 for <ipsec@ietf.org>; Wed, 25 Nov 2009 00:32:28 -0800 (PST)
X-CheckPoint: {4B0CE7DE-0-14201DC2-FFFF}
Received: by dlpdemo.checkpoint.com (Postfix, from userid 105) id 61F9729C008; Wed, 25 Nov 2009 10:32:19 +0200 (IST)
Received: from michael.checkpoint.com (michael.checkpoint.com [194.29.32.68]) by dlpdemo.checkpoint.com (Postfix) with ESMTP id 2FF0929C005; Wed, 25 Nov 2009 10:32:19 +0200 (IST)
X-CheckPoint: {4B0CE7DA-0-14201DC2-FFFF}
Received: from il-ex01.ad.checkpoint.com (localhost [127.0.0.1]) by michael.checkpoint.com (8.12.10+Sun/8.12.10) with ESMTP id nAP8WIGo001046; Wed, 25 Nov 2009 10:32:18 +0200 (IST)
Received: from il-ex01.ad.checkpoint.com ([126.0.0.2]) by il-ex01.ad.checkpoint.com ([126.0.0.2]) with mapi; Wed, 25 Nov 2009 10:32:24 +0200
From: Yoav Nir <ynir@checkpoint.com>
To: Paul Hoffman <paul.hoffman@vpnc.org>
Date: Wed, 25 Nov 2009 10:32:15 +0200
Thread-Topic: [IPsec] #117: Hash and URL interop
Thread-Index: Acptqc/0X4V08TEYTSCPOrQj2Ekh0w==
Message-ID: <EA6311DE-97C3-4633-AAD2-C6C82946D162@checkpoint.com>
References: <7F9A6D26EB51614FBF9F81C0DA4CFEC801BDA1213EA9@il-ex01.ad.checkpoint.com> <7F9A6D26EB51614FBF9F81C0DA4CFEC801BDF88DFFE1@il-ex01.ad.checkpoint.com> <p06240863c731d54f3a70@[10.20.30.158]>
In-Reply-To: <p06240863c731d54f3a70@[10.20.30.158]>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: IPsecme WG <ipsec@ietf.org>
Subject: Re: [IPsec] #117: Hash and URL interop
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipsec>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 25 Nov 2009 08:32:29 -0000

+1

Even things that seem obvious like https and ftp require a lot of considerations, like how to verify the certificate in https, or what identity to present in ftp.

If someone wants to specify additional URL methods, they can specify then in an I-D.

On Nov 24, 2009, at 8:24 PM, Paul Hoffman wrote:

> At 7:09 PM +0200 11/24/09, Yaron Sheffer wrote:
>> Resending. There may be value in other URL methods, just maybe, but OTOH they would confuse developers and add security issues.
> 
> I agree with only listing HTTP.
> 
> --Paul Hoffman, Director
> --VPN Consortium