[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: reserving some SAIDs



I haven't been keeping up with the ipsec stuff due to overload
but I think this is an excellent idea.  (See the "global SAID"
idea in my incomplete PIPS proposal.)

To my mind, any complete IP security proposal must make it possible to
send an isolated datagram without end to end set up.  This sort of
thing is the only way I can see to achieve that.

Donald

From:  Ran Atkinson <atkinson@sundance.itd.nrl.navy.mil>
To:  ipsec@ans.net
Sender:  atkinson@sundance.itd.nrl.navy.mil
>
>One subject that I've been asked about several times by IPv6 folks
>is whether we could reserve some SAID values.  These could be
>used for predefined meanings (e.g. use RSA with the public keys
>from the DNS to encrypt/decrypt this packet).  In the IPv6 drafts
>I'm proposing to reserve 0xFFFFFF01 through 0xFFFFFFFF for future
>use along these lines.
>
>Comments ??
>
>Ran
>atkinson@itd.nrl.navy.mil
>


Follow-Ups: References: