nanog mailing list archives
Re: AH is pretty useless and perhaps should be deprecated
From: Mohacsi Janos <mohacsi () niif hu>
Date: Sun, 15 Nov 2009 07:58:24 +0100 (CET)
On Sat, 14 Nov 2009, Jack Kohn wrote:
Hi, Interesting discussion on the utility of Authentication Header (AH) in IPSecME WG. http://www.ietf.org/mail-archive/web/ipsec/current/msg05026.html Post explaining that AH even though protecting the source and destination IP addresses is really not good enough. http://www.ietf.org/mail-archive/web/ipsec/current/msg05056.html What do folks feel? Do they see themselves using AH in the future? IMO, ESP and WESP are good enough and we dont need to support AH any more ..
They are planning to make OSPFv3 IPSec authentication useless? Best Regards, Janos Mohacsi
Current thread:
- Re: AH is pretty useless and perhaps should be deprecated, (continued)
- Re: AH is pretty useless and perhaps should be deprecated Joel Jaeggli (Nov 15)
- Re: AH is pretty useless and perhaps should be deprecated Jack Kohn (Nov 16)
- Re: AH is pretty useless and perhaps should be deprecated James Hess (Nov 16)
- Re: AH is pretty useless and perhaps should be deprecated Steven Bellovin (Nov 16)
- Re: AH is pretty useless and perhaps should be deprecated David Barak (Nov 16)
- Re: AH is pretty useless and perhaps should be deprecated Steven Bellovin (Nov 14)
- Re: AH is pretty useless and perhaps should be deprecated David Barak (Nov 14)
- Re: AH is pretty useless and perhaps should be deprecated Steven Bellovin (Nov 14)
- Re: AH is pretty useless and perhaps should be deprecated Marshall Eubanks (Nov 15)
- Re: AH is pretty useless and perhaps should be deprecated Merike Kaeo (Nov 15)
- Re: AH is pretty useless and perhaps should be deprecated Merike Kaeo (Nov 13)