Re: [IPsec] leading versus trailing ICV

2020-07-31 Thread Steffen Klassert
On Thu, Jul 30, 2020 at 10:13:57PM -0400, William Allen Simpson wrote: > The comments thus far seem to be mixed. This is a perennial topic. > We spent much time on it in PIPE/SIPP/IPv6. > > We agreed on leading for AH and trailing for ESP. > > When I wrote the KA9Q NOS code implementing Van Jaco

Re: [IPsec] multiple windows need multiple SPIs

2020-07-31 Thread Michael Rossberg
> On 7/24/20 2:28 PM, William Allen Simpson wrote: >> Therefore, I'd recommend that IPsec instead implement a block of related >> SPIs. >> Each SPI should have its unique session-key as usual, but all would have the >> same next protocol header and TCP/UDP port associated with the same flow. >> I

Re: [IPsec] leading versus trailing ICV

2020-07-31 Thread Michael Rossberg
> >> In modern CPUs, there's always an issue with cache lines. But for a >> parallel implementation, it really isn't going to matter. The CPU >> that finishes last and needs to check the ICV isn't particularly >> likely to be the CPU that processed the initial header anyway. > > While that wou

Re: [IPsec] Preliminary minutes from the IETF 108 IPsecME WG Meeting

2020-07-31 Thread Benjamin Kaduk
Hi Med, Yoav, all, On Wed, Jul 29, 2020 at 05:38:17AM +, mohamed.boucad...@orange.com wrote: > Hi Yoav, Ben, all, > > == > Ben (AD): (missed first point Belongs in ADD?) Slide with attribute format, > for DoH, need to provide URI template FWIW, the first point was not quite "belongs in ADD"