mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Jesse Pollard <pollard@tomcat.admin.navo.hpc.mil>
To: Venkateshr@ami.com,
	"'Jesse Pollard'" <pollard@tomcat.admin.navo.hpc.mil>,
	Venkatesh Ramamurthy <Venkateshr@ami.com>,
	"'Alan Cox'"@tomcat.admin.navo.hpc.mil,
	<alan@lxorguk.ukuu.org.uk>,
	Venkatesh Ramamurthy <Venkateshr@ami.com>
Cc: linux-kernel@vger.kernel.org
Subject: RE: [RFC] Direct Sockets Support??
Date: Thu, 3 May 2001 15:23:37 -0500 (CDT)	[thread overview]
Message-ID: <200105032023.PAA74826@tomcat.admin.navo.hpc.mil> (raw)

---------  Received message begins Here  ---------

> 
> 
> 	> Doesn't this bypass all of the network security controls? Granted
> - it is
> 	> completely reasonable in a dedicated environment, but I would
> think the
> 	> security loss would prevent it from being used for most usage.
> 
> 	Direct Sockets makes sense only in clustering (server farms) to
> reduce intra-farm communication. It is *not* supposed to be used for regular
> internet. Direct Sockets over subnets is also tough to implement it across
> different topology subnets. Fabrics like Infiniband provide security on
> hardware, so there is no need to worry about it. The simple point  is that
> hw supports TCP/IP, then why do we need a software TCP/IP over it?

Because the hardware doesn't have the users security context. All it can
see are addresses, socket numbers and protocol. Neither can it be extended
with that information (IPSec). Authentication of the connections are not
possible.

Now... If the server farm only runs one job at a time, it is irrelevent...

-------------------------------------------------------------------------
Jesse I Pollard, II
Email: pollard@navo.hpc.mil

Any opinions expressed are solely my own.

             reply	other threads:[~2001-05-03 20:24 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2001-05-03 20:23 Jesse Pollard [this message]
  -- strict thread matches above, loose matches on Subject: below --
2001-05-08 20:18 Venkatesh Ramamurthy
2001-05-08 20:50 ` Alan Cox
2001-05-08 21:32 ` 'Pete Wyckoff'
     [not found] <034670D62D19D31180990090277A37B701811D72@mercury.corp.iready.com>
2001-05-08 13:04 ` Alan Cox
2001-05-08 20:00   ` Pete Wyckoff
2001-05-03 20:55 Venkatesh Ramamurthy
2001-05-03 20:40 Venkatesh Ramamurthy
2001-05-03 21:52 ` Alan Cox
2001-05-03 19:25 Venkatesh Ramamurthy
2001-05-03 20:29 ` Alan Cox
2001-05-03 19:23 Jesse Pollard
2001-05-03 18:59 Venkatesh Ramamurthy
2001-05-03 20:17 ` Alan Cox
     [not found] <007901c0d3fd$ea3f0880$7253e59b@megatrends.com>
2001-05-03 18:34 ` Alan Cox

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200105032023.PAA74826@tomcat.admin.navo.hpc.mil \
    --to=pollard@tomcat.admin.navo.hpc.mil \
    --cc="'Alan Cox'"@tomcat.admin.navo.hpc.mil \
    --cc=Venkateshr@ami.com \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®