[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: pfs support
Hi Will,
Will Price wrote:
>
> Supporting PFS involves:
>
> 1. Doing a second key exchange with DH in Phase 2
> 2. Deleting the Phase 1 SA immediately after the Phase 2 to dispose of the
> key material involved
My interpretation is that there should be an "OR" between those. That
is, there is ID PFS and key PFS. I think ID PFS consists in negotiating
exactly one quick mode (qm) SA per main mode (mm) SA, and key pfs
consists in refreshing the key material (via a qm KE payload) for each
qm SA, with no requirement for deletion of the mm SA. That's not to say
that you can't delete the mm SA, but I don't interpret it as a
requirement. How do others interpret this?
Scott
Follow-Ups:
References: