Re: comments on draft-ietf-ipsec-pki-req-01.txt - alternate

"C. Harald Koch" <chk@utcc.utoronto.ca> Sat, 12 September 1998 17:16 UTC

Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id NAA01200 for ipsec-outgoing; Sat, 12 Sep 1998 13:16:03 -0400 (EDT)
Message-Id: <199809121732.NAA25373@penelope.ve3tla.ampr.org>
To: Rodney Thayer <rodney@tillerman.nu>
cc: bmanning@isi.edu, ipsec@tis.com
Subject: Re: comments on draft-ietf-ipsec-pki-req-01.txt - alternate
References: <199809111113.HAA06472@2gn.com> <199809112157.RAA02441@2gn.com>
In-reply-to: rodney's message of "Fri, 11 Sep 1998 18:55:35 -0400". <199809112157.RAA02441@2gn.com>
From: "C. Harald Koch" <chk@utcc.utoronto.ca>
X-uri: <URL:http://chk.home.ml.org/>
X-Face: )@F:jK?*}hv!eJ}*r*0DD"k8x1.d#i>7`ETe2; hSD2T!:Fh#wu`0pW7lO|Dfe'AbyNy[\Pw z'.bAtgTM!+iq2$yXiv4gf<:D*rZ-|f$\YQi7"D"=CG!JB?[^_7v>8Mm; z:NJ7pss)l__Cw+.>xUJ) did@Pr9
Date: Sat, 12 Sep 1998 13:32:22 -0400
Sender: owner-ipsec@ex.tis.com
Precedence: bulk

In message <199809112157.RAA02441@2gn.com>, Rodney Thayer writes:

> well since nobody else seems to care where the packet came from I suppose
> it's fine.

If you *do* care where the packet came from, then your local policy engine
should do the enforcement. The point is that "caring where the packet came
from" should *not* be a mandatory requirement of the standard. It's perfectly
valid to not care where the packet came from when you know *who* it came
from...

-- 
C. Harald Koch     <chk@utcc.utoronto.ca>

"It takes a child to raze a village."
		-Michael T. Fry