[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

question about draft semantics




Best ipsec mailing list members,

The following text is from draft-ietf-ipsec-arch-sec-01.txt: 

> 1.4  Minimal Essential Support
>
   ......

>
>   The following sequences of combinations of AH and ESP, each
>   represented by a separate security association, must be supported by an
>   IPsec-compliant host: AH, ESP (tunnel), ESP(transport), AH-ESP(transport),
>   AH-ESP(tunnel), ESP(tunnel)-AH, AH-ESP(tunnel)-ESP(transport), and
>   ESP(tunnel)-ESP(transport).
>
  ......


>Atkinson                                                        [Page 5]
>
>Internet Draft        Security Architecture for IP      10 November 1996

To me, this part of the text seems a bit unclear. I would interpret it
so, that the word "each" would refer to the word "combinations". Then
this text would in my opinion mean that e.g. the combination 
AH-ESP(transport) would have one SPI value, not one SPI value for AH
and one SPI for ESP(transport). Am I misinterpreting the text? Will
always all transforms have an SPI of their own?


	Kindly,

	Bengt Sahlin 




Follow-Ups: