Re: (IPng) out-of-band key management is like virtual ...

"Perry E. Metzger" <perry@imsi.com> Tue, 07 March 1995 23:16 UTC

Received: from interlock.ans.net by nis.ans.net with SMTP id AA04891 (5.65c/IDA-1.4.4 for <archive-ipsec@nis.ans.net>); Tue, 7 Mar 1995 18:16:35 -0500
Received: by interlock.ans.net id AA10955 (InterLock SMTP Gateway 3.0 for ipsec-out@ans.net); Tue, 7 Mar 1995 18:15:30 -0500
Message-Id: <199503072315.AA10955@interlock.ans.net>
Received: by interlock.ans.net (Protected-side Proxy Mail Agent-4); Tue, 7 Mar 1995 18:15:30 -0500
Received: by interlock.ans.net (Protected-side Proxy Mail Agent-3); Tue, 7 Mar 1995 18:15:30 -0500
Received: by interlock.ans.net (Protected-side Proxy Mail Agent-2); Tue, 7 Mar 1995 18:15:30 -0500
Received: by interlock.ans.net (Protected-side Proxy Mail Agent-1); Tue, 7 Mar 1995 18:15:30 -0500
To: "Housley, Russ" <housley@spyrus.com>
Cc: ipsec@ans.net
Subject: Re: (IPng) out-of-band key management is like virtual ...
In-Reply-To: Your message of "Tue, 07 Mar 1995 14:46:01." <9502077946.AA794616361@spysouth.spyrus.com>
Reply-To: perry@imsi.com
X-Reposting-Policy: redistribute only with permission
Date: Tue, 07 Mar 1995 18:13:24 -0500
From: "Perry E. Metzger" <perry@imsi.com>

"Housley, Russ" says:
> >As clearly described in the drafts, SAIDs are assigned at the pleasure 
> >of the entity controlling the destination address. The us of "entity 
> >controlling" rather than "destination host" was deliberate -- it was 
> >there because of multicast.
> 
> I agree that the SAID must me assigned by the entity controlling the 
> destination address.  In fact, this is exactly my point.  Key management 
> will do something different to establish a security association for two 
> IPSP peers than to establish a multicast security association.
> 
> The IPSP processing may well be identical once those security associations 
> are in place.

If you agree with that, then you are necessarily supporting the point
that structured SAIDs are not needed for multicast.

.pm