[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IPSEC Minutes - IETF28



Ran Atkinson writes:

>  Secondly, I think it would be ideal if the need for key management APIs
>were raised with the CAT working group as something that we'd like to
>see as an optional extension to their existing Generic Security Services
>Application Programming Interfaces (GSS-APIs).  They are already dealing
>with APIs and our identified need fits neatly with their existing work.

Many of the key management technologies being discussed in ipsec
could fit, I believe, as GSS-API mechanisms.  Perhaps a sufficient
extension would be a single call which allows a caller to extract
an established session key for arbitrary use?  I think it would be
a very Good Thing to avoid duplication of effort by enabling the
same technologies being built to establish keys for ipsec to also
be consumed by other applications.

--jl