Re: [IPsec] Closing some of the open tickets for IKEv2bis

2010-01-25 Thread Yoav Nir
On Jan 25, 2010, at 1:44 PM, Tero Kivinen wrote: > Yoav Nir writes: > >> Issue #141 - Silently deleting the Child SA after a CHILD_SA_NOT_FOUND >> == >> Section 2.25: "A peer that receives a CHILD_SA_NOT_FOUND >> notification SH

Re: [IPsec] Closing some of the open tickets for IKEv2bis

2010-01-25 Thread Tero Kivinen
Valery Smyslov writes: > I would suugest replacing current text from draft-07: > >For ESP and AH, a single Child SA negotiation results in two security >associations (one in each direction). Keying material MUST be taken >from th

[IPsec] Closing some of the open tickets for IKEv2bis

2010-01-25 Thread Tero Kivinen
Yoav Nir writes: > Issue #138 - Calculations involving Ni/Nr > = > Section 2.14: "only the first 64 bits of Ni and the first 64 bits of > Nr are used in the calculation". This section has two calculations > involving Ni/Nr, but this sentence should only apply

Re: [IPsec] Closing some of the open tickets for IKEv2bis

2010-01-24 Thread Valery Smyslov
Yoav Nir writes: > Issue #139 - Keying material taken in the order for RoHC > > One of the differences between RFC 4306 and the IKEv2bis draft is in Section 2.17, Generating Key Material for Child SAs. Appendix E.2 of the IKEv2bis draft indi

[IPsec] Closing some of the open tickets for IKEv2bis

2010-01-24 Thread Yoav Nir
Hi all We would like to begin closing IKEv2bis issue at a faster rate than we are opening new ones. Paul has sent the list a several issues. Some we have discussed, others - not so much. Here's a summary of three issues, which I think are ready for closure. Issue #138 - Calculations involvin