[119334] in North American Network Operators' Group
Re: AH is pretty useless and perhaps should be deprecated
daemon@ATHENA.MIT.EDU (Mohacsi Janos)
Sun Nov 15 01:59:14 2009
Date: Sun, 15 Nov 2009 07:58:24 +0100 (CET)
From: Mohacsi Janos <mohacsi@niif.hu>
To: Jack Kohn <kohn.jack@gmail.com>
In-Reply-To: <dc8fd0140911131622n38af24f6je4bc4c0b8b7ad9d9@mail.gmail.com>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Sat, 14 Nov 2009, Jack Kohn wrote:
> Hi,
>
> Interesting discussion on the utility of Authentication Header (AH) in
> IPSecME WG.
>
> http://www.ietf.org/mail-archive/web/ipsec/current/msg05026.html
>
> Post explaining that AH even though protecting the source and
> destination IP addresses is really not good enough.
>
> http://www.ietf.org/mail-archive/web/ipsec/current/msg05056.html
>
> What do folks feel? Do they see themselves using AH in the future?
> IMO, ESP and WESP are good enough and we dont need to support AH any
> more ..
They are planning to make OSPFv3 IPSec authentication useless?
Best Regards,
Janos Mohacsi