Re: [IPsec] Queries relating to ESP/AH GCM & GMAC

2011-04-11 Thread Tero Kivinen
david.bl...@emc.com writes: > It's more than a decision to not include that capability - IKEv1 exchanges > cannot be protected with combined mode algorithms without significant > incompatible change to IKEv1, as explained in Section 1 of RFC 5282: That is clear, I do not think anybody even dreams

Re: [IPsec] Queries relating to ESP/AH GCM & GMAC

2011-04-11 Thread david.black
Hi Tero, I think we're in violent agreement on: > I am very worried when people start implementing those ciphers to > IKEv1, as there is no way to know which features of the RFC4303 they > decide to include too. I agree that completely removing them is not > the way we want to go forward, but I w