Re: [MEXT] Review of draft draft-patil-mext-mip6issueswithipsec-01

"Kroeselberg, Dirk (NSN - DE/Munich)" <dirk.kroeselberg@nsn.com> Tue, 28 July 2009 08:24 UTC

Return-Path: <dirk.kroeselberg@nsn.com>
X-Original-To: mext@core3.amsl.com
Delivered-To: mext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D92293A6D3B for <mext@core3.amsl.com>; Tue, 28 Jul 2009 01:24:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level:
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id c4-N7jIHVy7S for <mext@core3.amsl.com>; Tue, 28 Jul 2009 01:24:03 -0700 (PDT)
Received: from demumfd001.nsn-inter.net (demumfd001.nsn-inter.net [217.115.75.233]) by core3.amsl.com (Postfix) with ESMTP id E48283A6D15 for <mext@ietf.org>; Tue, 28 Jul 2009 01:23:58 -0700 (PDT)
Received: from demuprx016.emea.nsn-intra.net ([10.150.129.55]) by demumfd001.nsn-inter.net (8.12.11.20060308/8.12.11) with ESMTP id n6S8NvBr004415 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL); Tue, 28 Jul 2009 10:23:57 +0200
Received: from demuexc023.nsn-intra.net (demuexc023.nsn-intra.net [10.150.128.36]) by demuprx016.emea.nsn-intra.net (8.12.11.20060308/8.12.11) with ESMTP id n6S8Nsfi017312; Tue, 28 Jul 2009 10:23:57 +0200
Received: from DEMUEXC030.nsn-intra.net ([10.150.128.57]) by demuexc023.nsn-intra.net with Microsoft SMTPSVC(6.0.3790.3959); Tue, 28 Jul 2009 10:23:55 +0200
X-MimeOLE: Produced By Microsoft Exchange V6.5
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Date: Tue, 28 Jul 2009 10:23:54 +0200
Message-ID: <8C51C7A529FC9D49843ACF5AE2FFBF67019CB73E@DEMUEXC030.nsn-intra.net>
In-Reply-To: <871vo18ccf.fsf@small.ssi.corp>
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: [MEXT] Review of draft draft-patil-mext-mip6issueswithipsec-01
Thread-Index: AcoPWakkjw6Qg8l+RsSZnai5O47hhQAAaorg
References: <C68F84FA.2B9FF%basavaraj.patil@nokia.com><87tz0xkjps.fsf@small.ssi.corp><9F72E813-4169-44E4-BA07-D70DC1C7070C@gmail.com> <871vo18ccf.fsf@small.ssi.corp>
From: "Kroeselberg, Dirk (NSN - DE/Munich)" <dirk.kroeselberg@nsn.com>
To: Arnaud Ebalard <arno@natisbad.org>, jouni korhonen <jouni.nospam@gmail.com>
X-OriginalArrivalTime: 28 Jul 2009 08:23:55.0995 (UTC) FILETIME=[BFA1F2B0:01CA0F5C]
Cc: Basavaraj.Patil@nokia.com, mext@ietf.org
Subject: Re: [MEXT] Review of draft draft-patil-mext-mip6issueswithipsec-01
X-BeenThere: mext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mobile IPv6 EXTensions WG <mext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/mext>, <mailto:mext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/mext>
List-Post: <mailto:mext@ietf.org>
List-Help: <mailto:mext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mext>, <mailto:mext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Jul 2009 08:24:03 -0000

Arnaud, 

> > [snip] relying on TLS (or even DTLS) for MIPv6 is IMHO a bad design
> > idea.
> >
> > Looks bad why? Please, list the points that lead to this 
> conclusion. I
> > would help us greatly.
> 
> - Because TLS has been designed to secure transport streams ..
> - ... not as a key exchange mechanism for L3

Would there be any technical problem with this? With EAP-TLS that you
are mentioning below, TLS does the same thing for L2.  

Thanks,
Dirk