All of lore.kernel.org
 help / color / mirror / Atom feed
From: Paul Moore <paul.moore@hp.com>
To: James Morris <jmorris@namei.org>
Cc: selinux@tycho.nsa.gov, Joy Latten <latten@us.ibm.com>,
	Venkat Yekkirala <vyekkirala@TrustedCS.com>
Subject: Re: Problems with Labeled IPsec, IKE and ECN
Date: Tue, 20 Nov 2007 17:30:12 -0500	[thread overview]
Message-ID: <200711201730.12250.paul.moore@hp.com> (raw)
In-Reply-To: <Xine.LNX.4.64.0711210729560.31381@us.intercode.com.au>

On Tuesday 20 November 2007 3:32:57 pm James Morris wrote:
> On Mon, 19 Nov 2007, Paul Moore wrote:
> > Needless to say this is a problem and we need to move away from using the
> > IKE/IPsec attribute value of "10" as soon as possible.  Further, simply
> > picking a new number is not a good solution, we should really petition
> > IANA to get an attribute number assigned for this purpose.  However,
> > doing so will most likely require documenting the Linux Labeled IPsec
> > design and submitting it to the IETF as a draft specification for
> > approval[4].
>
> How likely is this approach viable, given the moratorium on ISAKMP/IKE v1
> features?

I have no idea.  Although I would presume that the Labeled IPsec folks would 
want to provide IKEv2 functionality at some point.

> >  If this is not
> > possible we will need to start investigating alternatives as "poaching"
> > existing standards is not a viable, maintainable solution.
>
> Note (from http://www.iana.org/assignments/isakmp-registry)
>
> "The values 32001-32767 are reserved for private use amongst
> cooperating systems."
>
> If we can't get an official number for use with IKEv1, then perhaps this
> will be our only option.

This is one of the things I had in mind as an "alternative" but I think we are 
better served trying to get an attribute reserved.

-- 
paul moore
linux security @ hp

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

      reply	other threads:[~2007-11-20 22:31 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-11-19 20:17 Problems with Labeled IPsec, IKE and ECN Paul Moore
2007-11-20 20:32 ` James Morris
2007-11-20 22:30   ` Paul Moore [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200711201730.12250.paul.moore@hp.com \
    --to=paul.moore@hp.com \
    --cc=jmorris@namei.org \
    --cc=latten@us.ibm.com \
    --cc=selinux@tycho.nsa.gov \
    --cc=vyekkirala@TrustedCS.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.