Re: is manual keying mandatory

"Michael C. Richardson" <mcr@sandelman.ottawa.on.ca> Thu, 19 March 1998 14:11 UTC

Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id JAA16945 for ipsec-outgoing; Thu, 19 Mar 1998 09:11:31 -0500 (EST)
Message-Id: <199803191424.JAA10184@istari.sandelman.ottawa.on.ca>
To: William Dixon <wdixon@microsoft.com>
CC: ipsec@tis.com
Subject: Re: is manual keying mandatory
In-reply-to: Your message of "Wed, 18 Mar 1998 13:51:35 PST." <E301AC63A589D111B63100805F15808901000C18@red-msg-07.dns.microsoft.com>
Date: Thu, 19 Mar 1998 09:24:46 -0500
From: "Michael C. Richardson" <mcr@sandelman.ottawa.on.ca>
Sender: owner-ipsec@ex.tis.com
Precedence: bulk

-----BEGIN PGP SIGNED MESSAGE-----


>>>>> "William" == William Dixon <wdixon@microsoft.com> writes:

    William> Since we have put so much effort into IKE now, I don't think it
    William> should be a MUST.

  IKE took a lot of effort because it is complicated. All complicated systems
need good run time diagnostics tools. Manual keying is an important
diagnostic tool because it verifies that the problem isn't in the IPsec
portions. 
  If supporting a manual keying API requires too much memory, or something,
then alternate boot images may be an option.

   :!mcr!:            |  Sandelman Software Works Corporation, Ottawa, ON  
   Michael Richardson |Network and security consulting and contract programming
 Personal: <A HREF="http://www.sandelman.ottawa.on.ca/People/Michael_Richardson/Bio.html">mcr@sandelman.ottawa.on.ca</A>. PGP key available.
 Corporate: <A HREF="http://www.sandelman.ottawa.on.ca/SSW/">sales@sandelman.ottawa.on.ca</A>. 



-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: latin1
Comment: Processed by Mailcrypt 3.4, an Emacs/PGP interface

iQB1AwUBNREqrNiXVu0RiA21AQFl4wMAwLEFCj0YzaRtauWRThZuCe6DSEtbL4xo
ZMSGvd3IRpq9u4E1vk8gcJHoPRYwD4udL8hWsr1X6MSBlf3MoqEnuiUjT83+MYKl
hx0kZZcRGwDBLwKIRlpKEYl1JszOX5m5
=uGLV
-----END PGP SIGNATURE-----