[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Ikev2 Traffic Selector payload



Radia Perlman - Boston Center for Networking writes:
 > But here's the change that incorporates Valery's suggestion, I think:
 > 
 >    If the responder has multiple ranges, and can't choose, then he
 >    MUST choose the largest set that encompasses the first TSi and first TSr.

Radia,

Is there any real life motivation for this sort of
complication? What you're proposing to fix here
smells much more like it's just smoothing over
configuration errors, with the distinct
possibility that both wrong implementations and
changes of configuration will come back to bite
whomever was relying on this behavior.

IMO, it's worth considering whether we should make
the protocols less tolerant of screwups with crisp
semantics, vs trying to be more forgiving along
with murky semantics. It seems to me that DWIM 
semantics with security protocols is a pretty
treacherous road.

	    Mike