[IPsec] Dnsdir telechat review of draft-ietf-ipsecme-mib-iptfs-05

2022-10-11 Thread Ralf Weber via Datatracker
Reviewer: Ralf Weber Review result: Ready Moin! I'm the assigned reviewer of the DNS Directorate for this draft, however the draft does not reference DNS in any way. It looks good for an SNMP MIB draft, though having not done anything with SNMP for a couple of years now I'm not qualified to judge

[IPsec] Discussion of draft-pwouters-ipsecme-multi-sa-performance

2022-10-11 Thread Valery Smyslov
Hi all, as I promised at the last IETF meeting, this is my review of the draft-pwouters-ipsecme-multi-sa-performance draft. This is not a formal review of the document, but rather some speculations on how the solution may be simplified. Sorry that it took so long and please consider this as an i

Re: [IPsec] Discussion of draft-pwouters-ipsecme-multi-sa-performance

2022-10-11 Thread Michael Richardson
Valery Smyslov wrote: > My main problem with the draft is the concept of "Fallback SA". This SA > is treated specially in the draft, which I don't think is > necessary. For example, it must always be up so that the outgoing > packet can always be sent in case per-CPU SA does not e

Re: [IPsec] Discussion of draft-pwouters-ipsecme-multi-sa-performance

2022-10-11 Thread Valery Smyslov
Hi Michael, > Valery Smyslov wrote: > > My main problem with the draft is the concept of "Fallback SA". This SA > > is treated specially in the draft, which I don't think is > > necessary. For example, it must always be up so that the outgoing > > packet can always be sent in case

[IPsec] I-D Action: draft-ietf-ipsecme-ikev1-algo-to-historic-07.txt

2022-10-11 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the IP Security Maintenance and Extensions WG of the IETF. Title : Deprecation of IKEv1 and obsoleted algorithms Author : Paul Wouters Filename

Re: [IPsec] AD review of draft-ietf-ipsecme-ikev1-algo-to-historic-06

2022-10-11 Thread Paul Wouters
On Fri, Jul 15, 2022 at 6:06 PM Roman Danyliw wrote: > Hi! > > I performed an AD review of draft-ietf-ipsecme-ikev1-algo-to-historic-06. > Thanks for this work to formally move the community to IKEv2. > Sorry for the late reply. I thought I answered this, but I can't find a trace of it, so I app

Re: [IPsec] AD review of draft-ietf-ipsecme-ikev1-algo-to-historic-06

2022-10-11 Thread Paul Wouters
On Tue, 11 Oct 2022, Paul Wouters wrote: I'm not following the text saying that "algorithms [are left] in a state of 'MAY be used'".  For example, the following Type 3 transforms are deprecated in Section 7 of this document: AUTH_HMAC_MD5_96, AUTH_DES_MAC and AUTH_KPDK_MD5.  Howeve