Re: [IPsec] IPTFS and transport mode.

2020-05-07 Thread Valery Smyslov
Hi, > > Christian Hopps wrote: > The primary thing I'm suggesting here is that we define TFS transport mode in > a separate draft. I agree that transport mode should be described in a separate draft provided that a tunnel mode draft will allow easy adding of transport mode. > Whether we suppor

[IPsec] Matching of IKE ID on certificate subject and RDN ordering

2020-05-07 Thread Paul Wouters
Recently I had an interesting issue come up. I needed to generate a certificate with a specific OU= content that our openssl/python code couldn't do, and I switched to nss's cert-util to generate a cert of sets for a test. Then I noticed something strange. Let's say you have the following DN sp