[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

replay field size



There was clear consensus at the ANX IPSEC bakeoff last week to make the
size of the replay field 32-bits for both AH and ESP.  If we _must_ have
alignment for IPv4 IPSEC then the additional bits should be specified as
alignment.  No one wants to do 64-bit math for replay computation.  It's
silly.  In my opinion, IPv4 is misaligned for 64-bit hardware anyway and I
don't see the point of aligning the fields just to keep the protocol
consistent with IPv6.

I don't think this issue needs the Security AD to resolve.  I think we
already have consensus.  Let's hear now from anyone who absolutely must
have 64 bits or else move to revise AH and ESP to reflect consensus.  We
have much more interesting things to argue about.

Derrell