[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: pfs support



Hi Will,

Will Price wrote:
> 
> Supporting PFS involves:
> 
> 1. Doing a second key exchange with DH in Phase 2
> 2. Deleting the Phase 1 SA immediately after the Phase 2 to dispose of the
> key material involved

My interpretation is that there should be an "OR" between those. That
is, there is ID PFS and key PFS. I think ID PFS consists in negotiating
exactly one quick mode (qm) SA per main mode (mm) SA, and key pfs
consists in refreshing the key material (via a qm KE payload) for each
qm SA, with no requirement for deletion of the mm SA. That's not to say
that you can't delete the mm SA, but I don't interpret it as a
requirement. How do others interpret this?

Scott


Follow-Ups: References: