[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Simplifying IKE (was RE: Reliable delete notifies)



On Fri, 13 Oct 2000, Valery Smyslov wrote:
> > Photuris.  See OpenBSD.org
> 
> I know it well and I like it (especially its true stateless cookies). 
> However, it is not a real alternative to ISAKMP. It may be considered 
> as an alternative to IKE (as an "instantiation" of ISAKMP), but not 
> to ISAKMP itself.

That's true.  The question is whether there is any real need for an
alternative to ISAKMP.  The real alternative, as in Photuris, is simply
to design the data structures to suit the application, rather than
insisting that the application must be an "instantiation" of some more
general structure -- which typically is as much a hindrance as a help.

                                                          Henry Spencer
                                                       henry@spsystems.net




References: