[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Suggestion for SOI wrt PFS



> The ideal situation would be that the peers negotiate an IKE SA (with DH)
> and one or more IPsec SAs (not using DH). After a specified timeout (the
> forward secrecy interval), the peers forget SKEYSEED_d, and the next phase 2
> exchange would have to contain a DH. This DH would be used to generate the
> new SKEYSEED_d for subsequent exchanges.

So, why not just start a new phase 1 at this point?

					- Bill