[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: draft-ietf-ipsec-esp-v3-01.txt: extended sequence number
itojun,
> I've got some question regarding to extended sequence number documented
> in ESPv3 (01 draft). clarification is appreciated.
>
> In section 2.2.1, it is mentioned that higher 32bit of extended
> sequence number is included in ICV. If this is the case, I guess
> the use of extended sequence number MUST be negotiated by SA management
> protocol (instead of "SHOULD" in 01) as the use of extended sequence
> number changes the wire packet format used for ICV computation.
> if one end uses extended sequence number and the other doesn't, they
> will compute ICV differently.
>
> packet diagram in section 2 seems a little bit confusing with respect
> to extended sequence number case (sequence number in the diagram has
> only 32bits).
>
>itojun
You are correct that both ends must know when this feature is used
for an SA. We said "SHOULD" vs. "MUST" in case someone wanted to go
with manual configuration of this feature, but I would prefer MUST if
the WG concurs.
Figure 2 shows a bits-on-the-wire format, and so it is appropriate to
illustrate a 32-bit sequence number there.
Steve