[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ESP transform with RC5



In a galaxy far, far away, : Mon, 18 Mar 1996 16:08:28 EST
> swIPe was a long dead experiment. SKIP is a key management protocol,
> which fits in the same place in the stack as Photuris or Oakley.

  This was August 1995. Vendors wanted to interoperate *soon*
  swIPe was on the list because it was out there.
  SKIP as implemented by SunScreen (not IPsec based) was also out there.
  Neither had any likelyhood of being found on a 4Mb 486/33 running Win3.11.

> We already had perfectly good IPsec transforms written and in place,
> by the way.

  Yes. Which is why the other "options" were quickly discarded.

> The only difference I can see between IPsec and S/WAN is that S/WAN
> uses RC5 instead of something like 3DES. Can you correct me on this?

  The original "spec" said MD5 and DES. RSA quickly added RC5. Whether or
not anyone actually tested that I don't remember.

> The IETF, perhaps?

  :-)

  That was my suggestion actually. In the end, we (Milkyway Networks) didn't
have the scheduling flexibility to come up with anything to test. Our current
VPN is Entrust based. 


-- 
      mcr@milkyway.com       |     <A HREF="http://www.milkyway.com/">Milkyway Networks Corporation</A>
   Michael C. Richardson     |   Makers of the Black Hole firewall 
 Senior Research Specialist  | info@milkyway.com for BlackHole questions
 Home: <A HREF="http://www.sandelman.ocunix.on.ca/People/Michael_Richardson/Bio.html">mcr@sandelman.ocunix.on.ca</A>. 



Follow-Ups: References: