[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Heartbeats draft available



Scott G. Kelly writes:
> Whether "heartbeats" are sent in a phase 1 or phase 2 SA, they are
> essentially a feature of the SA. Features of SAs are currently
> configured (and negotiated) using SA attributes. Why would these be any
> different?

Because SA payloads does not allow responder to modify the proposal.
In heartbeat protocol this is almost mandatory feature, because the
responder is the one who is going to send the packets, thus he wants
to control the parameters.

Of course we could say that when using this special heartbeat
negotiation protocol, the responder is allowed to modify the SA, but
the SA payload is also little too complicated for very basic
negotiation (all the things about transforms, protocols and
proposals). 
-- 
kivinen@iki.fi                               Work : +358-9-4354 3218
SSH Communications Security                  http://www.ssh.fi/
SSH IPSEC Toolkit                            http://www.ssh.fi/ipsec/


References: