[119334] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: AH is pretty useless and perhaps should be deprecated

daemon@ATHENA.MIT.EDU (Mohacsi Janos)
Sun Nov 15 01:59:14 2009

Date: Sun, 15 Nov 2009 07:58:24 +0100 (CET)
From: Mohacsi Janos <mohacsi@niif.hu>
To: Jack Kohn <kohn.jack@gmail.com>
In-Reply-To: <dc8fd0140911131622n38af24f6je4bc4c0b8b7ad9d9@mail.gmail.com>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org




On Sat, 14 Nov 2009, Jack Kohn wrote:

> Hi,
>
> Interesting discussion on the utility of Authentication Header (AH) in
> IPSecME WG.
>
> http://www.ietf.org/mail-archive/web/ipsec/current/msg05026.html
>
> Post explaining that AH even though protecting the source and
> destination IP addresses is really not good enough.
>
> http://www.ietf.org/mail-archive/web/ipsec/current/msg05056.html
>
> What do folks feel? Do they see themselves using AH in the future?
> IMO, ESP and WESP are good enough and we dont need to support AH any
> more ..


They are planning to make OSPFv3 IPSec authentication useless?
Best Regards,
 	Janos Mohacsi



home help back first fref pref prev next nref lref last post