Merit Network
Can't find what you're looking for? Search the Mail Archives.
  About Merit   Services   Network   Resources & Support   Network Research   News   Events   Home

Discussion Communities: Merit Network Email List Archives

OpenCALEA

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical
RE: [OpenCALEA] standards compliance

  • From: Jesse Norell
  • Date: Tue Mar 20 15:04:04 2007

Implementing the ATIS draft should work, or providing all requisite
information in any format the LEA would accept (eg. a native "opencalea"
format) would work.  I don't know which would be better.

Assuming we'll pursue the ATIS standard, I think my other question needs
to be answered very soon, ie. does it require an ASN.1 implementation or
not.  Anyone have any ASN.1 coding skills?  I think that would be a good
approach to take, but I'm at ground zero on the ASN.1 learning curve.  I
don't mind taking that curve on, but someone else could probably cut
days/weeks of time off if they've already done that.

Also for the ATIS standard we're going to need some plugs/hooks into
different services to pull CmII information.  Eg. we have to be able to
report on dhcp address assignments, radius auth attempts, etc.  Some of
that would be staightforward to do in "tap", eg. it could fairly easily
parse dhcp packets; some of it gets a little hairier, eg. it could parse
radius packets, but then you have to keep a list of all your radius
secrets in place for all your radius clients.  And some of it would be
impractical in tap, eg. homegrown solutions that don't follow any
standard.  Perhaps a utility to report such information to the collector
would be the ticket.  Something can be done to gather the info on the
dhcp server and use that utility to report it; something different on
the radius server; and any homegrown solutions have a nice piece to hook
in wherever it's appropriate.

Some of the ATIS stuff is administrative level, as well, eg. the Annex C
stuff (not part of the standard, but still useful for completeness and
for those who need the vpn pieces for compliance).




On Tue, 2007-03-20 at 14:26 -0400, Manish Karir wrote:
> 
> The goal with OpenCALEA was to create a public and open implementation
> of 
> the standard (whatever that standard is).  The assumption is that the
> current ATIS draft standard will eventually become a full-blown 
> standard(acceptable to LEA)  and if not then there has to be *some*
> public 
> document that shows what format LEA expects, and OpenCALEA should be
> able 
> to implement that.

-- 
Jesse Norell - jesse@kci.net
Kentec Communications, Inc.





Discussion Communities


About Merit | Services | Network | Resources & Support | Network Research
News | Events | Contact | Site Map | Merit Network Home


Merit Network, Inc.