(E-Mail Removed) (Stephen J. Bevan) writes:
[...]
> BTW it is not that I think IKE+IPsec is perfect by any means, it is
> just that it isn't clear to me that any of the alternative are
> better.
FWIW, N. Ferguson and B. Schneier did an analysis on IPsec and a
summary of their conclusion is:
We are of two minds about IPsec. On the one hand, IPsec is far
better than any IP security protocol that has come before:
Microsoft PPTP, L2TP, etc. On the other hand, we do not believe
that it will ever result in a secure operational system. It is
far too complex, and the complexity has lead to a large number of
ambiguities, contradictions, ine ciencies, and weaknesses. [...]
We strongly discourage the use of IPsec in its current form for
protection of any kind of valuable information, and hope that
future iterations of the design will be improved. However, we
even more strongly discourage any current alternatives, and
recommend IPsec when the alternative is an insecure network. Such
are the realities of the world.
http://www.counterpane.com/ipsec.html
--
David Magda <dmagda at ee.ryerson.ca>,
http://www.magda.ca/
Because the innovator has for enemies all those who have done well under
the old conditions, and lukewarm defenders in those who may do well
under the new. -- Niccolo Machiavelli, _The Prince_, Chapter VI