[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

apology




I did not intend to impune Greg Minshall's character in my earlier note.
He had been open in previous face-to-face discussions (e.g. in the hallways
at USENIX) about the advantages of open ports for the Ipsilon product. He
says his concerns about open ports predate Ipsilon and I take him at his
word on that.

If the user didn't want the ports and transport-layer covered up, then the
user would have used an upper-layer security service (e.g. PEM, PGP, SSL,
whatever) instead of IPsec.  Uncovering the ports within the context of
IPsec is unwise and contrary to the intent of the IPsec work.

Ran
rja@inet.org



Follow-Ups: