[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: How to select SPD



K SrinivasRao wrote:
> 
> Hello,
> 
> In case of automatic key managent, when the initiator sends multiple
> proposals to the responder, the responder has to select one of the
> proposal. For this he has to check the proposals that has been sent against
> what he can support which are present in his SPD. But how he will select
> which incoming SPD entry he has to use? Where do we get the selectors to
> select an SPD entry? We will get src and dest IP address from the packet,
> but that is not sufficient for selecting an SPD entry.

The ID payload also supports (one) protocol/port pair, and you could
also include other ID types in that payload (ASN.1 {DN | GN}, Key ID).



Follow-Ups: References: