[IPsec] AD review comments for draft-ietf-ipsecme-ikev2bis

2010-03-29 Thread Sean Turner
Here is my AD review for draft-ietf-ipsecme-ikev2bis-08. I read this from the perspective of: I just picked this up how do I implement this. I found nothing wrong with the protocol, but there were lots of things that could be done to make this a bit easier to read (at least from my perspectiv

Re: [IPsec] New PAKE Criteria draft posted (def. of gateway)

2010-03-29 Thread Raj Singh
Hi Team, The similar scenarios are beautifully handled by Redirect RFC-5685. The Redirect RFC emphasize on client-gateway terminology, which is typical use of Redirect mechanism in IKEv2 where Gateway redirects client to another less loaded gateway but at the same time RFC is also applicable to ro

Re: [IPsec] New PAKE Criteria draft posted (def. of gateway)

2010-03-29 Thread Tero Kivinen
Yaron Sheffer writes: > I'm not suggesting to constrain the protocol. I'm trying to focus the > discussion, and focus the criteria. We both know that integrating an > existing PAKE into IKEv2 is not such a big deal. But we can spend months > debating password management: > > - Do we specify a p