Re: [IPsec] FW: I-D Action:draft-nir-ike-nochild-00.txt

2009-05-25 Thread Yoav Nir
Hi Raj > 3. Also, why its a VID payload, Notify suits better. Because a third > party client will want to connect to some other server. Please give > justification for IKE_AUTH_NO_CHILD to be a VID. Section 3.12 of -bis document says "A Vendor ID payload MAY announce that the sender is capable o

Re: [IPsec] Inconsistent usage of SA

2009-05-25 Thread Stephen Kent
At 10:11 AM -0400 5/22/09, Gunduzhan, Emre wrote: Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_068F06DC4D106941B297C0C5F9F446EA3CB241D203aplesstripedo_" Greetings, I am new to this group, so I hope I am not raising an issue which was addressed earlier. I

Re: [IPsec] WG Last Call: draft-ietf-ipsecme-ikev2-resumption-04.txt

2009-05-25 Thread Paul Hoffman
[[ Just a nudge. It would be great to hear from folks who have read this document before the end of this week. If you are active in the WG but haven't read the document, please do: it's not that long. --Paul ]] At 1:06 PM -0700 5/15/09, Paul Hoffman wrote: >Greetings again. There has been almost

[IPsec] IKEv2: RADIUS

2009-05-25 Thread Matthew Cini Sarreo
Hello All, My apologies if this has already been asked. We are interested to have our implementation of IKEv2 to provide support for authentication with a RADIUS server. We did this in IKEv1 by implementing XAuth. For IKEv2, the only resource that seems to tackle this is http://www.employees.org/