Stephen Kent | 1 Mar 2007 04:25
Picon

Re: core doc outstanding issues

At 8:47 AM -0600 2/21/07, Nicolas Williams wrote:
>On Wed, Feb 21, 2007 at 09:22:02AM -0500, Stephen Kent wrote:
>>  At 12:30 PM -0600 2/20/07, Nicolas Williams wrote:
>>  >It would help to have a more formal description of the PAD.
>>
>>  yes, that could help, but I think I've pointed to text in 4301 that
>>  shows why the example on the slide was not a good one.
>
>Not a good one, perhaps, but not incorrect either (below I think out
>loud to convince myself that it's not a good example).  As I explained
>at the meeting at IETF66 one might prefer to to use names instead of
>TSes for SPD searches if referential integrity between the PAD and the
>SPD using IP addresses is harder to maintain than using IDs -- which it
>might well be.
>
>I'll make the following changes to the I-D and submit:
>
>  - change those example PAD entries (all non-BTNS ones) to search the
>    SPD by IP address
>
>  - change the example SPDs to have a separate column for name, if I
>    still have any PAD entries specifying tha the SPD be searched by ID
>
>  - add a better description of how the whole PAD constrains the TSes
>    that BTNS peers can assert for their child SAs
>
>Now for the thinking out loud...
>
>Suppose we use certs with iPAddress SANs, then the PAD can be very
>simple, and the SPD can be very simple also, with only the PAD
(Continue reading)

Nicolas Williams | 1 Mar 2007 05:44
Picon

Re: core doc outstanding issues

BTW, I've submitted a new version of btns-core.  And also a new version
of btns-connection-latching.
_______________________________________________

Nicolas Williams | 1 Mar 2007 05:26
Picon

Re: core doc outstanding issues

On Wed, Feb 28, 2007 at 10:25:28PM -0500, Stephen Kent wrote:
> So, the question is whether this example is sufficiently compelling 
> to warrant a change to the PAD and SPD text too accommodate it. Also, 
> we need to note that this is not intended to be used by SGs, just by 
> individual hosts, right?

No, it's not sufficiently compelling -- as I wrote, that was a stream of
consciousness whereby I convinced myself that the example in our I-D was
not a good one.  It sufficed to have validation of that thought process;
answers to the additional questions therein would be a plus, but not
necessary.
_______________________________________________


Gmane