[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Child_SA key material



Section 4.16 of draft-ietf-ipsec-ikev2-03.txt
describes how key material is taken from KEYMAT
for CHILD-SAs.

If AH and ESP were negotiated would the key material 
be taken as

    1. AH_in, AH_out, ESP_in(encr, auth), ESP_out(encr, auth)

          or

    2. AH_in, ESP_in(encr, auth), AH_out, ESP_out(encr, auth)

David