[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[no subject]
- <!--x-content-type: text/plain --> "http://www.w3.org/TR/html4/loose.dtd">
- <!--x-date: Mon Sep 28 10:54:16 2009 -->
- <!--x-from-r13: Gaxabja -->
- <!--x-message-id: 68dc8536a648f422932270acec227139@NO-ID-FOUND.mhonarc.org -->
- <!--x-subject: -->
- <li><em><!--x-content-type</em>: text/plain --> "http://www.w3.org/TR/html4/loose.dtd"></li>
- <li><em><!--x-date</em>: Mon Sep 28 10:48:35 2009 --></li>
- <li><em><!--x-from-r13</em>: Gaxabja --></li>
- <li><em><!--x-message-id</em>: <a href="mailto:b5bcc35c3e04e60356346d22b11c9960%40NO">b5bcc35c3e04e60356346d22b11c9960@NO</a>&#45;ID&#45;FOUND.mhonarc.org --></li>
- <li><em><!--x-subject</em>: --></li>
- <li><em><li><em>&lt;!--x-content-type</em></em>: text/plain --&gt;</li></li>
- <li><em><li><em>&lt;!--x-date</em></em>: Tue, 8 Apr 2003 19:03:52 &amp;#45;0400 --&gt;</li></li>
- <li><em><li><em>&lt;!--x-from-r13</em></em>: Oycre Krtva &lt;nycreNqbpbzbynof&amp;#45;hfn.pbz&gt; --&gt;</li></li>
- <li><em><li><em>&lt;!--x-message-id</em></em>: <a href="mailto:BAB8A241.49F5%25alper%40docomolabs"><a href="mailto:BAB8A241.49F5%25alper%40docomolabs">BAB8A241.49F5%alper@docomolabs</a></a>&amp;#45;usa.com --&gt;</li></li>
- <li><em><li><em>&lt;!--x-reference</em></em>: <a href="mailto:1049805209.3243.71.camel%40localhost.localdomain"><a href="mailto:1049805209.3243.71.camel%40localhost.localdomain">1049805209.3243.71.camel@localhost.localdomain</a></a> --&gt;</li></li>
- <li><em><li><em>&lt;!--x-subject</em></em>: Re: [Seamoby] LWAPP --&gt;</li></li>
- <li><em><li><em>&lt;h1&gt;re</em></em>: [Seamoby] LWAPP&lt;/h1&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;cc&lt;/em&gt;</em></em>: &amp;lt;&lt;a href=&quot;mailto:<a href="mailto:seamoby%40ietf.org"><a href="mailto:seamoby%40ietf.org">seamoby@ietf.org</a></a>&quot;&gt;<a href="mailto:seamoby%40ietf.org"><a href="mailto:seamoby%40ietf.org">seamoby@ietf.org</a></a>&lt;/a&gt;&amp;gt;, &amp;lt;&lt;a href=&quot;mailto:<a href="mailto:skelly%40airespace.com"><a href="mailto:skelly%40airespace.com">skelly@airespace.com</a></a>&quot;&gt;<a href="mailto:skelly%40airespace.com"><a href="mailto:skelly%40airespace.com">skelly@airespace.com</a></a>&lt;/a&gt;&amp;gt;, &amp;lt;&lt;a href=&quot;mailto:<a href="mailto:rsuri%40airespace.com"><a href="mailto:rsuri%40airespace.com">rsuri@airespace.com</a></a>&quot;&gt;<a href="mailto:rsuri%40airespace.com"><a href="mailto:rsuri%40airespace.com">rsuri@airespace.com</a></a>&lt;/a&gt;&amp;gt;, &amp;lt;&lt;a href=&quot;mailto:<a href="mailto:bob%40airespace.com"><a href="mailto:bob%40airespace.com">bob@airespace.com</a></a>&quot;&gt;<a href="mailto:bob%40airespace.com"><a href="mailto:bob%40airespace.com">bob@airespace.com</a></a>&lt;/a&gt;&amp;gt;, Glen Zorn &amp;lt;&lt;a href=&quot;mailto:<a href="mailto:gwz%40cisco.com"><a href="mailto:gwz%40cisco.com">gwz@cisco.com</a></a>&quot;&gt;<a href="mailto:gwz%40cisco.com"><a href="mailto:gwz%40cisco.com">gwz@cisco.com</a></a>&lt;/a&gt;&amp;gt;, &amp;lt;&lt;a href=&quot;mailto:<a href="mailto:funato%40docomolabs-usa.com"><a href="mailto:funato%40docomolabs-usa.com">funato@docomolabs-usa.com</a></a>&quot;&gt;<a href="mailto:funato%40docomolabs-usa.com"><a href="mailto:funato%40docomolabs-usa.com">funato@docomolabs-usa.com</a></a>&lt;/a&gt;&amp;gt;&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;date&lt;/em&gt;</em></em>: Tue, 08 Apr 2003 15:58:57 -0700&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;from&lt;/em&gt;</em></em>: Alper Yegin &amp;lt;&lt;a href=&quot;mailto:<a href="mailto:alper%40docomolabs-usa.com"><a href="mailto:alper%40docomolabs-usa.com">alper@docomolabs-usa.com</a></a>&quot;&gt;<a href="mailto:alper%40docomolabs-usa.com"><a href="mailto:alper%40docomolabs-usa.com">alper@docomolabs-usa.com</a></a>&lt;/a&gt;&amp;gt;&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;in-reply-to&lt;/em&gt;</em></em>: &amp;lt;&lt;a href=&quot;msg01928.html&quot;&gt;<a href="mailto:1049805209.3243.71.camel%40localhost.localdomain"><a href="mailto:1049805209.3243.71.camel%40localhost.localdomain">1049805209.3243.71.camel@localhost.localdomain</a></a>&lt;/a&gt;&amp;gt;&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;list-help&lt;/em&gt;</em></em>: &amp;lt;&lt;a href=&quot;mailto:<a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dhelp"><a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dhelp">seamoby-request@ietf.org?subject=help</a></a>&quot;&gt;mailto:<a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dhelp"><a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dhelp">seamoby-request@ietf.org?subject=help</a></a>&lt;/a&gt;&amp;gt;&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;list-id&lt;/em&gt;</em></em>: Context Transfer,Handoff Candidate Discovery,and Dormant Mode Host Alerting &amp;lt;seamoby.ietf.org&amp;gt;&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;list-post&lt;/em&gt;</em></em>: &amp;lt;&lt;a href=&quot;mailto:<a href="mailto:seamoby%40ietf.org"><a href="mailto:seamoby%40ietf.org">seamoby@ietf.org</a></a>&quot;&gt;mailto:<a href="mailto:seamoby%40ietf.org"><a href="mailto:seamoby%40ietf.org">seamoby@ietf.org</a></a>&lt;/a&gt;&amp;gt;&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;list-subscribe&lt;/em&gt;</em></em>: &amp;lt;&lt;a href=&quot;https://www1.ietf.org/mailman/listinfo/seamoby&quot;&gt;https://www1.ietf.org/mailman/listinfo/seamoby&lt;/a&gt;&amp;gt;,&amp;lt;&lt;a href=&quot;mailto:<a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dsubscribe"><a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dsubscribe">seamoby-request@ietf.org?subject=subscribe</a></a>&quot;&gt;mailto:<a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dsubscribe"><a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dsubscribe">seamoby-request@ietf.org?subject=subscribe</a></a>&lt;/a&gt;&amp;gt;&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;list-unsubscribe&lt;/em&gt;</em></em>: &amp;lt;&lt;a href=&quot;https://www1.ietf.org/mailman/listinfo/seamoby&quot;&gt;https://www1.ietf.org/mailman/listinfo/seamoby&lt;/a&gt;&amp;gt;,&amp;lt;&lt;a href=&quot;mailto:<a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dunsubscribe"><a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dunsubscribe">seamoby-request@ietf.org?subject=unsubscribe</a></a>&quot;&gt;mailto:<a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dunsubscribe"><a href="mailto:seamoby-request%40ietf.org%3Fsubject%3Dunsubscribe">seamoby-request@ietf.org?subject=unsubscribe</a></a>&lt;/a&gt;&amp;gt;&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;sender&lt;/em&gt;</em></em>: &lt;a href=&quot;mailto:<a href="mailto:seamoby-admin%40ietf.org"><a href="mailto:seamoby-admin%40ietf.org">seamoby-admin@ietf.org</a></a>&quot;&gt;<a href="mailto:seamoby-admin%40ietf.org"><a href="mailto:seamoby-admin%40ietf.org">seamoby-admin@ietf.org</a></a>&lt;/a&gt;&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;subject&lt;/em&gt;</em></em>: Re: [Seamoby] LWAPP&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;li&gt;&lt;em&gt;to&lt;/em&gt;</em></em>: Pat Calhoun &amp;lt;&lt;a href=&quot;mailto:<a href="mailto:pcalhoun%40bstormnetworks.com"><a href="mailto:pcalhoun%40bstormnetworks.com">pcalhoun@bstormnetworks.com</a></a>&quot;&gt;<a href="mailto:pcalhoun%40bstormnetworks.com"><a href="mailto:pcalhoun%40bstormnetworks.com">pcalhoun@bstormnetworks.com</a></a>&lt;/a&gt;&amp;gt;&lt;/li&gt;</li></li>
- <li><em><li><em>&lt;title&gt;re</em></em>: [Seamoby] LWAPP&lt;/title&gt;</li></li>
How does what you have in mind compare/relate to the above draft?
&amp;gt;
&amp;gt;&amp;gt; I'm not sure
&amp;gt;&amp;gt; what exactly you mean by &amp;quot;secure interface&amp;quot;, but based on my reading of the
&amp;gt;&amp;gt; draft the only security is for protecting this protocol's packets between
&amp;gt;&amp;gt; the AP and the AR. And this is not an additional feature but a requirement
&amp;gt;&amp;gt; on the protocol.
&amp;gt;
&amp;gt; Correct - that is the secure interface I mentioned. It is assumed that
&amp;gt; the user will protect his/her own traffic... and that the AR will
&amp;gt; enforce whatever policy it has defined. LWAPP was not intended to
&amp;gt; replace end-to-end security, but securing that interface *is* a
&amp;gt; requirement, not an additional feature. A malicious AP can do very nasty
&amp;gt; things to an AR.
&amp;gt;
&amp;gt;&amp;gt;&amp;gt;
&amp;gt;&amp;gt;&amp;gt; Further, the market has made it pretty clear that they no longer want
&amp;gt;&amp;gt;&amp;gt; smart APs that have to be managed individually. They want a central
&amp;gt;&amp;gt;&amp;gt; point of control, with remote interfaces. But this is a market issue,
&amp;gt;&amp;gt;&amp;gt; not a standards one.
&amp;gt;&amp;gt;
&amp;gt;&amp;gt; This makes sense. But is there any difference between your proposed protocol
&amp;gt;&amp;gt; and SNMP in this context?
&amp;gt;
&amp;gt; Sure, let me explain.
&amp;gt;
&amp;gt; What we've heard from our customers is that they are tired to managing
&amp;gt; APs scattered throughout their networks (oh, and it's clear the industry
&amp;gt; is moving in this direction, these are not just my own ramblings). The
&amp;gt; issue SNMP in the AP is that it does require the administrator to touch
&amp;gt; the device. People want a secure plug and play solution. If SNMP is on
&amp;gt; the box, you must configure the community string (and user in the case
&amp;gt; of v3), and this security relationship is one that must be administered
&amp;gt; over the course of the device's lifetime. The market is pretty clear in
&amp;gt; the fact that it wants an AP that can auto-discover ARs and establish a
&amp;gt; security relationship w/o any administrator involvement. The draft's use
&amp;gt; of certificates provides this feature, but I agree that a shared secret
&amp;gt; mechanism should probably be defined as well.
If I'm understanding this right, the problem is that SNMP does not know how
to use certificates for authentication.... I don't know how hard it is to
solve this if it is needed as you described....
alper
&amp;gt;
&amp;gt; PatC
&amp;gt;
&amp;gt; _______________________________________________
&amp;gt; Seamoby mailing list
&amp;gt; Seamoby@ietf.org
&amp;gt; &lt;a href=&quot;<a rel="nofollow" href="<a rel="nofollow" href="https://www1.ietf.org/mailman/listinfo/seamoby&quot"">https://www1.ietf.org/mailman/listinfo/seamoby&quot"</a>;><a rel="nofollow" href="https://www1.ietf.org/mailman/listinfo/seamoby&quot">https://www1.ietf.org/mailman/listinfo/seamoby&quot</a></a>;&gt;<a rel="nofollow" href="<a rel="nofollow" href="https://www1.ietf.org/mailman/listinfo/seamoby"">https://www1.ietf.org/mailman/listinfo/seamoby"</a>;><a rel="nofollow" href="https://www1.ietf.org/mailman/listinfo/seamoby">https://www1.ietf.org/mailman/listinfo/seamoby</a></a>&lt;/a&gt;
&amp;gt;
_______________________________________________
Seamoby mailing list
Seamoby@ietf.org
&lt;a href=&quot;<a rel="nofollow" href="<a rel="nofollow" href="https://www1.ietf.org/mailman/listinfo/seamoby&quot"">https://www1.ietf.org/mailman/listinfo/seamoby&quot"</a>;><a rel="nofollow" href="https://www1.ietf.org/mailman/listinfo/seamoby&quot">https://www1.ietf.org/mailman/listinfo/seamoby&quot</a></a>;&gt;<a rel="nofollow" href="<a rel="nofollow" href="https://www1.ietf.org/mailman/listinfo/seamoby"">https://www1.ietf.org/mailman/listinfo/seamoby"</a>;><a rel="nofollow" href="https://www1.ietf.org/mailman/listinfo/seamoby">https://www1.ietf.org/mailman/listinfo/seamoby</a></a>&lt;/a&gt;
&lt;/pre&gt;
&lt;!--X-Body-of-Message-End--&gt;
&lt;!--X-MsgBody-End--&gt;
&lt;!--X-Follow-Ups--&gt;
&lt;hr&gt;
&lt;!--X-Follow-Ups-End--&gt;
&lt;!--X-References--&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;References&lt;/strong&gt;:
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a name=&quot;01928&quot; href=&quot;msg01928.html&quot;&gt;Re: [Seamoby] LWAPP&lt;/a&gt;&lt;/strong&gt;
&lt;ul&gt;&lt;li&gt;&lt;em&gt;From:&lt;/em&gt; Pat Calhoun &amp;lt;pcalhoun@bstormnetworks.com&amp;gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;!--X-References-End--&gt;
&lt;!--X-BotPNI--&gt;
&lt;ul&gt;
&lt;li&gt;Prev by Date:
&lt;strong&gt;&lt;a href=&quot;msg01932.html&quot;&gt;RE: [Seamoby] LWAPP&lt;/a&gt;&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Next by Date:
&lt;strong&gt;&lt;a href=&quot;msg01934.html&quot;&gt;RE: [Seamoby] LWAPP&lt;/a&gt;&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Previous by thread:
&lt;strong&gt;&lt;a href=&quot;msg01928.html&quot;&gt;Re: [Seamoby] LWAPP&lt;/a&gt;&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Next by thread:
&lt;strong&gt;&lt;a href=&quot;msg01927.html&quot;&gt;Re: [Seamoby] LWAPP&lt;/a&gt;&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Index(es):
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;maillist.html#01933&quot;&gt;&lt;strong&gt;Date&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;thrd2.html#01933&quot;&gt;&lt;strong&gt;Thread&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;!--X-BotPNI-End--&gt;
&lt;!--X-User-Footer--&gt;
&lt;!--X-User-Footer-End--&gt;
&lt;/body&gt;
&lt;/html&gt;
</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg01930.html">[no subject]</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg01932.html">[no subject]</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg01930.html">[no subject]</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg01932.html">[no subject]</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#01931"><strong>Date</strong></a></li>
<li><a href="threads.html#01931"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>
<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>
</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg01930.html">[no subject]</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg01932.html">[no subject]</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg01930.html">[no subject]</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg01932.html">[no subject]</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#01931"><strong>Date</strong></a></li>
<li><a href="threads.html#01931"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>
<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>