[TICTOC] WGLC on NTS: Why not run over IPsec?

Sharon Goldberg <goldbe@cs.bu.edu> Wed, 23 March 2016 08:02 UTC

Return-Path: <sharon.goldbe@gmail.com>
X-Original-To: tictoc@ietfa.amsl.com
Delivered-To: tictoc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 52B1C12DA08 for <tictoc@ietfa.amsl.com>; Wed, 23 Mar 2016 01:02:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.349
X-Spam-Level:
X-Spam-Status: No, score=-2.349 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.249, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KaOArIrYxxSA for <tictoc@ietfa.amsl.com>; Wed, 23 Mar 2016 01:02:22 -0700 (PDT)
Received: from mail-wm0-x22a.google.com (mail-wm0-x22a.google.com [IPv6:2a00:1450:400c:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 817A112D8A6 for <tictoc@ietf.org>; Wed, 23 Mar 2016 01:02:22 -0700 (PDT)
Received: by mail-wm0-x22a.google.com with SMTP id l68so222334589wml.0 for <tictoc@ietf.org>; Wed, 23 Mar 2016 01:02:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:from:date:message-id:subject:to; bh=0ujFA+B7w8XTdbw0zICcCIum2oySBtrgj2EVbp7pyis=; b=ds+zxH60vDRUM34ck/VugUvQ/AwEnAFjgqQLCsmBfig0mxUlXLGixkmW1n1YMSmIz5 WbU96H5WCd4/j6kE+TxHJY6Pr7B/2+Ae90J8ysFdtKV9JF9OoapZau5FnLeod2AYNoz9 JqYzoraTUDRSTV4WJ2wWl0JRrn1J55hjtuJx32bC4mXcRZ4IrhUbqU6XTdKQDNgcCgoa M0qXhq+J2v+I9WyFgnRNXoUfrejCLSHEWxXBDmWDSt86LtXWvD/eeXQRJQUvcRwaazGi pAlp1QOmsUPQAFGmNP1Hzk5rBRdko+vgrC2BDuZqfbJq6j/Xbq2KxqsLMBDiGDW94O2i 7KlQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:sender:from:date:message-id:subject :to; bh=0ujFA+B7w8XTdbw0zICcCIum2oySBtrgj2EVbp7pyis=; b=kexN0FCJSMeHsQ4QVY1aha1mBmSkxpxxmJEeyjz0ey75Uyjy+urj2o/KpfFd7M8vod Ty2+NVPkF1spI67DSlce6x+xLfc3FaXpn/QAuGQJ8/U7vFFemC2mJf/Exx/hdVGNXCoC lfk9ub06gyPm7urc+2VCjfuFu9xXUj1gayn1PHs4CmHP+t3qa6W4I87+8gbmuAeT+pKg eQAZBig5sD5m6jtcvaXsab/UXVVF1kF6DrtJuHlvEPpjVm318pug5/ZfcinQo3BMw7Rb fnnI7TkF52HT0RJAXAYwiHUHO8oL9U8ji/qG/PX+cYtIctA7f640QMRlSJP8VwMmSEyV pSwg==
X-Gm-Message-State: AD7BkJJrcxKjcA94OmdLOyVJuWU78YDtvzkejDTfkieuMfLIYsNL4ToXzg94J+zyoh4x5xLAaf4oEu5rHeK6Dw==
X-Received: by 10.28.174.72 with SMTP id x69mr24381407wme.68.1458720141036; Wed, 23 Mar 2016 01:02:21 -0700 (PDT)
MIME-Version: 1.0
Sender: sharon.goldbe@gmail.com
Received: by 10.194.242.35 with HTTP; Wed, 23 Mar 2016 01:01:41 -0700 (PDT)
From: Sharon Goldberg <goldbe@cs.bu.edu>
Date: Wed, 23 Mar 2016 04:01:41 -0400
X-Google-Sender-Auth: _MZ37ulCWgH9p_iQpslt9Ny8H-0
Message-ID: <CAJHGrrQH0Ce+UFTy6m=SrzTk0AWmBFywC88HccHy0+WG16ibdQ@mail.gmail.com>
To: tictoc@ietf.org, ntpwg@lists.ntp.org
Content-Type: multipart/alternative; boundary="001a114444e0d54f93052eb2bf69"
Archived-At: <http://mailarchive.ietf.org/arch/msg/tictoc/Ax6wEbrFibGkY9wn6NDtFQ5O0RE>
X-Mailman-Approved-At: Wed, 23 Mar 2016 02:07:38 -0700
Subject: [TICTOC] WGLC on NTS: Why not run over IPsec?
X-BeenThere: tictoc@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Timing over IP Connection and Transfer of Clock BOF <tictoc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tictoc>, <mailto:tictoc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tictoc/>
List-Post: <mailto:tictoc@ietf.org>
List-Help: <mailto:tictoc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tictoc>, <mailto:tictoc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Mar 2016 08:02:24 -0000

Dear WG,

Another question, and please forgive me if this was discussed already and I
missed it.

It would be helpful to know why NTS is not just just running over IPsec. (I
can see why running NTP over TLS makes little sense, since TLS runs over
TCP while NTP runs over UDP so everything would probably
break.) But NTP runs over IP. I suppose there are some performance
hits to using IPsec? What are they?

Thanks,
Sharon

-- 
Sharon Goldberg
Computer Science, Boston University
http://www.cs.bu.edu/~goldbe