Re: [IPsec] leading versus trailing ICV

2020-08-01 Thread William Allen Simpson
On 7/31/20 4:32 AM, Steffen Klassert wrote: Architectures can change the 2 byte NET_IP_ALIGN if they prefer DMA alignment over IP alignment. As I mentioned in an earlier email, my most recent RFC work is RDMA. While that would be possible for some algorithms, I've never seen that a single c

Re: [IPsec] multiple windows need multiple SPIs

2020-08-01 Thread William Allen Simpson
On 7/31/20 4:37 AM, Michael Rossberg wrote: Somehow associated SAs would perhaps allow us to derive/install a key locally on demand. Correct. In the original IPsec design, as we had specified that there could be multiple SPIs per SA, the definition of SA was broader than later editors. Ho