[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: draft-ietf-ipsec-ciph-cbc-02.txt



   Date: Mon, 16 Mar 1998 18:10:22 -0500
   From: Bill Sommerfeld <sommerfeld@orchard.arlington.ma.us>

   I'm a little leery about this, because it means that different
   implementations would have different ideas about what constitutes a
   weak key, which could lead to rarely-occurring, difficult-to-diagnose
   interoperability glitches when the shared key ends up being "weak" and
   one endpoint detects this and the other doesn't.

I wouldn't think this should cause an interoperability glitch, since
either side should already be able to force that an SA be negotiated,
for a variety of reasons, including one where one of the security
gateway reboots and loses state.  (This is general case problem may be
one of the places where we need some implementation and operatonal
experience before we're sure we've gotten all of the details right.)

						- Ted



References: