RE: [NSIS] AD Review comments on draft-ietf-nsis-req-07.txt

john.loughney@nokia.com Tue, 17 June 2003 05:56 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id BAA18019 for <nsis-archive@odin.ietf.org>; Tue, 17 Jun 2003 01:56:40 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h5H5uBm10102 for nsis-archive@odin.ietf.org; Tue, 17 Jun 2003 01:56:11 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h5H41Ga01419; Tue, 17 Jun 2003 00:01:16 -0400
Received: from ietf.org (lists.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h5H40mm01352 for <nsis@optimus.ietf.org>; Tue, 17 Jun 2003 00:00:48 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA15596 for <nsis@ietf.org>; Tue, 17 Jun 2003 00:00:44 -0400 (EDT)
From: john.loughney@nokia.com
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19S7c5-0002Gs-00 for nsis@ietf.org; Mon, 16 Jun 2003 23:58:29 -0400
Received: from mgw-x1.nokia.com ([131.228.20.21]) by ietf-mx with esmtp (Exim 4.12) id 19S7c4-0002Gn-00 for nsis@ietf.org; Mon, 16 Jun 2003 23:58:29 -0400
Received: from esvir05nok.ntc.nokia.com (esvir05nokt.ntc.nokia.com [172.21.143.37]) by mgw-x1.nokia.com (Switch-2.2.6/Switch-2.2.6) with ESMTP id h5H40ha04034 for <nsis@ietf.org>; Tue, 17 Jun 2003 07:00:43 +0300 (EET DST)
Received: from esebh003.NOE.Nokia.com (unverified) by esvir05nok.ntc.nokia.com (Content Technologies SMTPRS 4.2.5) with ESMTP id <T62e0f9842eac158f258d8@esvir05nok.ntc.nokia.com>; Tue, 17 Jun 2003 07:00:43 +0300
Received: from esebe003.NOE.Nokia.com ([172.21.138.39]) by esebh003.NOE.Nokia.com with Microsoft SMTPSVC(5.0.2195.6139); Tue, 17 Jun 2003 07:00:43 +0300
Received: from esebe023.NOE.Nokia.com ([172.21.138.115]) by esebe003.NOE.Nokia.com with Microsoft SMTPSVC(5.0.2195.6139); Tue, 17 Jun 2003 07:00:43 +0300
X-MimeOLE: Produced By Microsoft Exchange V6.0.6375.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Subject: RE: [NSIS] AD Review comments on draft-ietf-nsis-req-07.txt
Date: Tue, 17 Jun 2003 07:00:40 +0300
Message-ID: <DADF50F5EC506B41A0F375ABEB32063658EEA0@esebe023.ntc.nokia.com>
Thread-Topic: [NSIS] AD Review comments on draft-ietf-nsis-req-07.txt
Thread-Index: AcM0TTesmPgTSA3ZQA2lIRTcj+fz4QAN4Khw
To: Attila.Bader@eth.ericsson.se, mankin@psg.com
Cc: nsis@ietf.org
X-OriginalArrivalTime: 17 Jun 2003 04:00:43.0380 (UTC) FILETIME=[06146340:01C33485]
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by www1.ietf.org id h5H40nm01360
Sender: nsis-admin@ietf.org
Errors-To: nsis-admin@ietf.org
X-BeenThere: nsis@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/nsis>, <mailto:nsis-request@ietf.org?subject=unsubscribe>
List-Id: Next Steps in Signaling <nsis.ietf.org>
List-Post: <mailto:nsis@ietf.org>
List-Help: <mailto:nsis-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/nsis>, <mailto:nsis-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 8bit

Hi Attila,

> I do not completely understand your argument for MUST 
> implementation of hop-by-hop security. 'Must be implemented 
> but not must use' means that there is the possibility to use 
> hop-by-hop security in any NE but it has to be implemented 
> even if it is never used. 'SHOULD be supported' means that it 
> has to be implemented except in particular cases. I think it 
> is strong enough. 

We are designing this for the Internet (see the 'I' in the 
IETF).  This being so, security is extremely important and
is needed to ensure a robust protocol that is resistant
to DoS attacks; protects infrastructure, etc.  In this
way:

 Channel security between signaling entities MUST be implemented.

seems perfectly reasonable.  Sysadmins, etc., can decide if
it needs to be turned on or not.

John
_______________________________________________
nsis mailing list
nsis@ietf.org
https://www1.ietf.org/mailman/listinfo/nsis