[119340] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: AH is pretty useless and perhaps should be deprecated

daemon@ATHENA.MIT.EDU (Joel Jaeggli)
Sun Nov 15 23:49:44 2009

Date: Mon, 16 Nov 2009 13:48:47 +0900
From: Joel Jaeggli <joelja@bogus.com>
To: Owen DeLong <owen@delong.com>
In-Reply-To: <C5F8CA90-10BF-4AA9-93AD-7504966F0E00@delong.com>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

Owen DeLong wrote:
> I've never seen anyone use AH vs. ESP.

OSPFv3?

>  I've always used ESP and so has
> every other IPSEC implementation I've seen anyone do.
> 
> Owen
> 
> On Nov 13, 2009, at 4:22 PM, Jack Kohn wrote:
> 
>> Hi,
>>
>> Interesting discussion on the utility of Authentication Header (AH) in
>> IPSecME WG.
>>
>> http://www.ietf.org/mail-archive/web/ipsec/current/msg05026.html
>>
>> Post explaining that AH even though protecting the source and
>> destination IP addresses is really not good enough.
>>
>> http://www.ietf.org/mail-archive/web/ipsec/current/msg05056.html
>>
>> What do folks feel? Do they see themselves using AH in the future?
>> IMO, ESP and WESP are good enough and we dont need to support AH any
>> more ..
>>
>> Jack
> 
> 


home help back first fref pref prev next nref lref last post