[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

AH and ESP othogoanlity



I agree that there are merits performing integrity along with encapsulation.
The only problem I see with it is that there will be deployments for IPSEC
in the very near future and most of the the implementations have implemented
RFC's 1828 and 1829. We definitely cannot stop this as many customers have
been asking for it.

This may cause configuration problems for old implementation (implementing
only 1829) to interoperate with the newer implementation which may support
both 1829 and the new transform. Can we allocated numbers to the transforms
as most of the key management protocols do so that configuring with manual
keying is simplified?

--Naganand



Follow-Ups: