Re: [IPsec] Closing some of the open tickets for IKEv2bis

2010-01-25 Thread Yoav Nir
On Jan 25, 2010, at 1:44 PM, Tero Kivinen wrote: > Yoav Nir writes: > >> Issue #141 - Silently deleting the Child SA after a CHILD_SA_NOT_FOUND >> == >> Section 2.25: "A peer that receives a CHILD_SA_NOT_FOUND >> notification SH

Re: [IPsec] Closing some of the open tickets for IKEv2bis

2010-01-25 Thread Tero Kivinen
Valery Smyslov writes: > I would suugest replacing current text from draft-07: > >For ESP and AH, a single Child SA negotiation results in two security >associations (one in each direction). Keying material MUST be taken >from th

Re: [IPsec] Closing some of the open tickets for IKEv2bis

2010-01-24 Thread Valery Smyslov
Yoav Nir writes: > Issue #139 - Keying material taken in the order for RoHC > > One of the differences between RFC 4306 and the IKEv2bis draft is in Section 2.17, Generating Key Material for Child SAs. Appendix E.2 of the IKEv2bis draft indi