[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ESP revisions straw poll



Dan and Matt,

	If you ship AH by itself, you will be have an authention-only
offering, but it won't be a complete IPSEC.  That's fine for IPv4, and
non-comliant for IPv6.  For IP v6 compliance, both AH and ESP are required,
thus whether we include or exclude an encryptionless mode of ESP will not
affect the export license status of IPv6 implementations that, as required,
support IPSEC.

	For IPv4, you are right that having an encryptionless mode of ESP
will not make it easier to export  ESP, but then it won't make it any
harder either.  I don't know about the rest of the WG members, but I do
have personal experience in  getting export licenses for crypto technology
I have developed at BBN, so I appreciate what is involved.  Nonetheless,
the bottom line is that this proposed feature set for ESP will not change
its export status.  I don't think that I suggested otherwise in the
discussion, but I apologize if anyone misunderstood the intent of the
proposal.

Steve




Follow-Ups: References: