[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: WG last call for IPv4 AH and ESP




"William Allen Simpson" says:
> Things have quieted down on this list about AH and ESP, so I have to
> assume we are ready to implement.  I'm working on integrating Ran's IPv6
> changes into the text.  Are there any other issues still unresolved?

I think there are two important things still unresolved; one fairly
small, one a bunch bigger.

The question of the proper way to combine authentication and
encryption is still outstanding; several people have excellent
arguments on why the keyed hash (or whatever) should be outside of the
encrypted area and several people have excellent arguments on why it
should be inside. I've avoided thinking about it for a couple of
weeks.

There is also the question of ICMP messages, which I'm worrying about
right now; part of the reason I've been putting this off is to see
what turns up while I implement.

Other than that, I think that the AH and ESP stuff are pretty much
done with.

Perry


References: