Re: draft-simpson-esp-des1-v2-00.txt to Draft Standard

Steven Bellovin <smb@research.att.com> Fri, 23 May 1997 23:21 UTC

Received: from cnri by ietf.org id aa21176; 23 May 97 19:21 EDT
Received: from portal.ex.tis.com by CNRI.Reston.VA.US id aa13755; 23 May 97 19:21 EDT
Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id TAA28003 for ipsec-outgoing; Fri, 23 May 1997 19:07:00 -0400 (EDT)
Message-Id: <199705232309.TAA20267@raptor.research.att.com>
To: William Allen Simpson <wsimpson@greendragon.com>
cc: ipsec@tis.com
Subject: Re: draft-simpson-esp-des1-v2-00.txt to Draft Standard
Date: Fri, 23 May 1997 19:09:33 -0400
From: Steven Bellovin <smb@research.att.com>
Sender: owner-ipsec@ex.tis.com
Precedence: bulk

	 Jeff Schiller (the Security Area Director) has indicated that:
	     RFC-1829 is the product of the IPSEC working group. It is for the
	     working group to decide whether or not to advance it. I will happi
	ly
	     act upon a recommendation of the working group as communicated to 
	me
	     by the chair.
	 
	 As interoperability has been demonstrated between 2 or more
	 implementations, I ask that this document be immediately forwarded
	 (within a few days) to the Area Director for advancement to Draft
	 Standard.

I'm afraid I disagree; this document is not ready for advancement.
First, it's the wrong document.  Given the new structure (i.e., as
described in draft-ietf-ipsec-new-esp-00.txt), there's far too much
in your draft.  The CAST-128 draft (draft-ietf-ipsec-esp-cast-128-cbc-00.txt)
or RC5-CBC draft (draft-ietf-ipsec-esp-rc5-cbc-00.txt) are much better
models for what's needed.  (Bill, I realize you feel differently.  I
don't like documents that overspecify stuff -- changes to the base
document's headers would require changes to your document as well,
quite unnecessarily.)

Second, given the new structure -- with authentication folded in with
ESP -- I don't know of any implementations.  I suppose one could say
that the DES-CBC part is ready, but it's a bit hard to assess without
the framework.