[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
question about draft semantics
Best ipsec mailing list members,
The following text is from draft-ietf-ipsec-arch-sec-01.txt:
> 1.4 Minimal Essential Support
>
......
>
> The following sequences of combinations of AH and ESP, each
> represented by a separate security association, must be supported by an
> IPsec-compliant host: AH, ESP (tunnel), ESP(transport), AH-ESP(transport),
> AH-ESP(tunnel), ESP(tunnel)-AH, AH-ESP(tunnel)-ESP(transport), and
> ESP(tunnel)-ESP(transport).
>
......
>Atkinson [Page 5]
>
>Internet Draft Security Architecture for IP 10 November 1996
To me, this part of the text seems a bit unclear. I would interpret it
so, that the word "each" would refer to the word "combinations". Then
this text would in my opinion mean that e.g. the combination
AH-ESP(transport) would have one SPI value, not one SPI value for AH
and one SPI for ESP(transport). Am I misinterpreting the text? Will
always all transforms have an SPI of their own?
Kindly,
Bengt Sahlin
Follow-Ups: