[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: draft-ietf-ipsec-esp-v3-01.txt: extended sequence number



itojun,

>	I've got some question regarding to extended sequence number documented
>	in ESPv3 (01 draft).  clarification is appreciated.
>
>	In section 2.2.1, it is mentioned that higher 32bit of extended
>	sequence number is included in ICV.  If this is the case, I guess
>	the use of extended sequence number MUST be negotiated by SA management
>	protocol (instead of "SHOULD" in 01) as the use of extended sequence
>	number changes the wire packet format used for ICV computation.
>	if one end uses extended sequence number and the other doesn't, they
>	will compute ICV differently.
>
>	packet diagram in section 2 seems a little bit confusing with respect
>	to extended sequence number case (sequence number in the diagram has
>	only 32bits).
>
>itojun

You are correct that both ends must know when this feature is used 
for an SA.  We said "SHOULD" vs. "MUST" in case someone wanted to go 
with manual configuration of this feature, but I would prefer MUST if 
the WG concurs.

Figure 2 shows a bits-on-the-wire format, and so it is appropriate to 
illustrate a 32-bit sequence number there.

Steve