[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: RESPONDER-LIFETIME Notify question



Hi Will,

Will Fiveash wrote:
> 
> Let's say as an initiator my code receives a notify RESPONDER-LIFETIME in
> the second Quick Mode message and the life duration isn't allowed by the
> local security policy.  Currently my code will delete the Phase 2 SA and
> send a SA delete notify to the remote system.  Do I need to send some sort
> of notify to tell the other side why I deleted the SA?
> 
> --
> Will Fiveash
> IBM AIX System Development (IPsec/IKE)

The current notify message draft suggests sending
ATTRIBUTES-NOT-SUPPORTED in this case.

Scott


References: