[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: (IPng) out-of-band key management is like virtual ...
Folks,
> Without such a designator, how do you expect to handle these
> cases?
Maybe what would be useful would be to allot part of the SAID space
for "not assigned by the destination system" (but not implying any
particular "structure"). I think this would make assignment easier.
Whether or not such an allocation is made, an implementation should be
able to solve the collision problem by making <SAID, destination
address> the key, instead of simply <SAID>. Then multicast
address(es) and locally assigned unicast address(es) could have the
same 32-bit SAID without "collision". One might also want some
wildcard address that would match any of the system's unicast
addresses (but not any multicast address); a question for the security
experts.
Charlie
Follow-Ups: