[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Quick Mode HASH(3) and optional payloads



RFC2409 (IKE) section 5.5 (Phase 2 - Quick Mode) describes HASH(3) in
a way that does not specify that optional payloads should be included.
[The whole wording for hashing of optional payloads and other payload
orders seems to be tacked on in an unfortunate way.]

I think that optional payloads should be fed into the hash function,
after Nr_b.  This would make HASH(3) more like HASH(1) and HASH(2).
It would also provide checking for these optional payloads.

- am I right in thinking that optional payloads are allowed in the
  initiator's second Quick Mode message?

- am I right that the RFC does not specify that the HASH(3) includes
  optional payloads?

- is there a good reason not to include the optional payloads in
  HASH(3)?

- is there a good reason to include the optional payloads in HASH(3)?

Hugh Redelmeier
hugh@mimosa.com  voice: +1 416 482-8253



Follow-Ups: