[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: QoS selectors (was LAST CALL: IKE)



On Tue, 1 Jul 2003, Stephen Kent wrote:
> >The only thing that comes to mind is to add a notify payload when 
> >rekeying that identifies the SPI of
> >the SA being rekeyed. But this is a bits on wire change...
>
> ...Using the SPI to identify an SA being rekeyed avoids ambiguity, no 
> matter what the source, and that seems worthwhile.

This sounds like an excellent idea.  One substantial headache with IKEv1
was the extent to which the responding end had to *guess* what the
initiating end was really trying to do.  The fewer such ambiguities there
are, the better. 

                                                          Henry Spencer
                                                       henry@spsystems.net