Re: is manual keying mandatory (fwd)
"Paul Lambert"<plambert@certicom.com> Sat, 21 March 1998 01:36 UTC
Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id UAA03390 for ipsec-outgoing; Fri, 20 Mar 1998 20:36:51 -0500 (EST)
X-Lotus-FromDomain: CERTICOM
From: Paul Lambert <plambert@certicom.com>
To: dfox@BayNetworks.COM
cc: ipsec@tis.com, John O Goyo <jgoyo@certicom.com>
Message-ID: <882565CE.000907C0.00@domino_c02.certicom.com>
Date: Fri, 20 Mar 1998 17:41:21 -0800
Subject: Re: is manual keying mandatory (fwd)
Sender: owner-ipsec@ex.tis.com
Precedence: bulk
>>From a practical standpoint, Diffie-Hellman is >extremely expensive in lessor-powered CPU's This is good reason retain and fix the elliptic curve options in Oakley. It's much faster and a better system solution than manual keys. Paul dfox@BayNetworks.COM on 03/20/98 10:46:22 AM Please respond to dfox@BayNetworks.COM To: adams@cisco.com cc: rgm-sec@htt-consult.com, jhwilson@austin.ibm.com, ipsec@tis.com (bcc: Paul Lambert/Certicom) Subject: Re: is manual keying mandatory (fwd) >From a practical standpoint, Diffie-Hellman is extremely expensive in lessor-powered CPU's, and in an environment where IP interfaces are coming up and down in a dynamic environment (say PPP over demand-dial ISDN lines), doing Diffie-Hellman again and again may be more taxing on the CPU than Triple DES encryption on full throughput. In such an environment, one can use a different KMP than ISAKMP/Oakley. But it would be beneficial to know that a completely inexpensive key management system (manual keying) is universally supported in all IP Security implementations. My customers would then be able to make the choice themselves whether to go with (relatively expensive) automated keying or (relatively inexpensive) manual keying, regardless of the IPSec-capable devices they were interfacing with. For this reason, I feel it is necessary to keep manual keying support a MUST. -- Daniel C. Fox <dfox@baynetworks.com> Software Project Leader Tel: +1 978-916-4216 Remote Access Server Division Fax: +1 978-916-4789 Bay Networks, Inc. <http://www.baynetworks.com>
- is manual keying mandatory Roy Pereira
- RE: is manual keying mandatory William Dixon
- Re: is manual keying mandatory Derrell D. Piper
- Re: is manual keying mandatory Bill Sommerfeld
- Re: is manual keying mandatory Dan McDonald
- Re: is manual keying mandatory (fwd) Jackie Wilson
- Re: is manual keying mandatory Bronislav Kavsan
- Re: is manual keying mandatory Perry E. Metzger
- Re: is manual keying mandatory (fwd) Perry E. Metzger
- Re: is manual keying mandatory Michael C. Richardson
- Re: is manual keying mandatory (fwd) Paul Koning
- Re: is manual keying mandatory Phil Servita
- Re: is manual keying mandatory (fwd) Robert Moskowitz
- Re: is manual keying mandatory Robert Moskowitz
- Re: is manual keying mandatory (fwd) Larry Backman
- FW: is manual keying mandatory Roy Pereira
- Re: is manual keying mandatory (fwd) Robert Moskowitz
- RE: is manual keying mandatory (fwd) Rob Adams
- Re: is manual keying mandatory Steve Sneddon
- RE: is manual keying mandatory Bede McCall
- Re: is manual keying mandatory Daniel Harkins
- Re: is manual keying mandatory Bronislav Kavsan
- [Fwd: is manual keying mandatory] Bronislav Kavsan
- Re: is manual keying mandatory Theodore Y. Ts'o
- Re: is manual keying mandatory (fwd) Daniel C. Fox
- Re: is manual keying mandatory (fwd) Paul Lambert
- Re: is manual keying mandatory Steve Sneddon
- Re: is manual keying mandatory Michael Richardson
- Re: is manual keying mandatory Dave Carrel
- Re: is manual keying mandatory Bronislav Kavsan
- Re: is manual keying mandatory Bronislav Kavsan
- Re: is manual keying mandatory Dave Carrel
- RE: is manual keying mandatory Bede McCall
- Re: is manual keying mandatory EKR
- Re: is manual keying mandatory Bronislav Kavsan
- RE: is manual keying mandatory Bede McCall
- Re: is manual keying mandatory Derrell D. Piper
- Re: is manual keying mandatory Perry E. Metzger
- Re: is manual keying mandatory Bronislav Kavsan
- Re: is manual keying mandatory Steve Sneddon
- Re: is manual keying mandatory Ran Atkinson
- Re: is manual keying mandatory (fwd) Hilarie Orman