mglt / draft-mglt-nvo3-geneve-security-requirements

0 stars 1 forks source link

definition of geneve security mechanism #6

Open mglt opened 6 years ago

mglt commented 6 years ago

Section 2: Paragraph beginning with SEC-GEN: We should remove references to new protocols or design of a specific solution. There is no rationale for a new protocol design while existing mechanisms would suffice.

mglt commented 6 years ago

The protocols have been mentioned as examples, and I believe this is clarifying to the reader. I see that as a nit and if the WG prefer to remove them I will be fine with that. Do you agree with this as a way to move forward ?

""" In the case new protocol needs to be design, the document strongly recommend to re-use existing security protocols like IP Security (IPsec) [RFC4301] and Datagram Transport Layer Security (DTLS) [RFC6347], and existing encryption algorithms (such as [RFC8221]), and authentication protocols. """