[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

IKE attributes consistency.

Shoichi 'Ne' Sakane writes:
> we need a consistent rule all over the attribute parsing, so:
> (1) we always attach the same attributes, for all transforms.
> (2) apply suggestion in ippcp draft section 4.1 to all transforms.
>     if there's no attribute, ignore it (if it is mandatory, bark).

The group parameter is attached to quick mode itself not to any
protocol inside the SA proposals. Thats why it the RFC2409 says it
MUST be included in all proposals. I think we should keep it that way,
and fix the draft-shacham-ippcp-rfc2393bis-06 to say that at least
group parameter MUST be accepted there.
kivinen@ssh.fi                               Work : +358 303 9870
SSH Communications Security                  http://www.ssh.fi/
SSH IPSEC Toolkit                            http://www.ssh.fi/ipsec/

Follow-Ups: References: