[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Deletion of SA
> K> negotiated a new SA and will use that for future
> K> communications. Should H1 send a delete payload to delete H2's
>
> Yes. That should occur as part of the new SA being setup.
> A question though: is a "delete" too strong here? Perhaps a "please
> delete this SA in X seconds" would be more appropriate? As a notify
> perhaps? That would allow SA's to be negotiated in advance of being
> used, and it also allows the network to drain.
> Someone tell me that this is already addressed, but I just missed
> that part :-)
Alternatively, you could put the burden of not sending the delete
until the *sender* has reason to believe that all relevant traffic has
drained from the net...
For instance, in the case of per-connection keying, the sender could
send a delete once the connection closed..
Follow-Ups:
References: