[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: (IPng) out-of-band key management is like virtual ...



Folks,

> Without such a designator, how do you expect to handle these
> cases?

Maybe what would be useful would be to allot part of the SAID space
for "not assigned by the destination system" (but not implying any
particular "structure").  I think this would make assignment easier.

Whether or not such an allocation is made, an implementation should be
able to solve the collision problem by making <SAID, destination
address> the key, instead of simply <SAID>.  Then multicast
address(es) and locally assigned unicast address(es) could have the
same 32-bit SAID without "collision".  One might also want some
wildcard address that would match any of the system's unicast
addresses (but not any multicast address); a question for the security
experts.

Charlie


Follow-Ups: