[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Text suggestion on computing keymat for rekey
To compute keymat for any SA, both sides need to agree on which side is
initiator.
While this is obvious for new SAs, the text is unclear about rekeys, eg
if the original
responder is the initiator of a rekey, which end is considered initiator
of the of the
new SA for puposes of computing keymat? After some SF hallway
discussions, the
general impression I got was that there is some value to keeping the
original initiator
as initiator of the rekeyed SA, (ie for management purposes this
approach doesnt allow
a rekey to hide which end was original initiator). As such, I propose
adding the
following text to the end of section 2.8:
"For purposes of computing keying material for the rekeyed SA, the
original initiator
of the SA is to be considered initiator of the rekeyed SA."
Jeff