nanog mailing list archives

Re: MACsec SFP


From: Saku Ytti <saku () ytti fi>
Date: Tue, 24 Jun 2014 20:19:53 +0300

On (2014-06-24 12:30 -0400), Christopher Morrow wrote:

it's going to be hard to schedule a key roll then, right? I would
expect that in most/many deployments where someone enters a 'key'
there has to be some compliance process that includes: "And you change
that key every X days" right? So you'll NOT want to be in a situation
that involves coordinating a few thousand truck rolls every X months
to have this deployed.

Hopefully you could offer date when new keys take effect.

Maybe some customer would then enter need for this in CLI in their multimillion
dollar RFQ, and then we'd get the feature.

maybe so... multi-million of sfp is a lot of sfp though.

Of course this would be for the equipment where SFP sits, SFP vendor can't
solve this. But if you're making it mandatory in router RFQ, it seems pretty
much guaranteed vendors would comply and winning bid at least would implement
it.


-- 
  ++ytti


Current thread: