[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SPIs, etc.



>  Phil Karn is right that the SPI number spaces should be separate for AH
>and ESP because they are different protocols.

Right. And for this same reason I've argued that there should be
separate attribute lists in Photuris for AH and ESP. These are
independent protocols with their own orthogonal options and number
spaces.

I'd like to add language something like the following to future
versions of the AH and ESP documents:

	Implementations MUST accept and properly process incoming "nested"
	security packets, i.e., packets using both the AH and ESP, where the
	SPIs for AH and ESP are the same. Implementations SHOULD be capable of
	generating nested packets with the same SPIs for AH and ESP, but they
	MAY be configured not to do so.

Phil


References: