[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ISAKMP null transforms



Dan,

>I don't see the problem here. If you don't want to do AH you shouldn't worry
>about your peer getting any message about your ability to do it. The only
>thing your peer cares about is what you intend on doing-- how you intend
>on communicating.

Well, I'm not sure I agree.  When I send a list of transforms in some
order, I implicitly state both a list of capabilities (all members
on the list) and an ordering of preferences.  Not "wanting" to do
AH doesn't imply that I'm not "willing" to do it should my peer deem
it necessary.  I would like to say "I'd prefer no AH, but here's
what I'll accept in order of preference: blah blah".

>  The second phase of negotiation establishes security associations. There is
>no such thing as a "null" security association. You can't do AH with nothing,
>same for ESP.
>
>  Dan

True, but I'm suggesting that an accepted "null" AH proposal would be
identical to accepting a proposal with no AH.

Cheers,
Brett


Follow-Ups: