Re: [IPsec] Question on RFC 5723 Session Resumption

2020-08-30 Thread Tero Kivinen
Michael Richardson writes: > > We added a suspend commend, but since that deleted states on the > > initiator, it ended up sending delete's to the server. The server > > deleted the IKE SAs. Now the client can resume a connection that > > technically was ended by Delete. > > It see

Re: [IPsec] Question on RFC 5723 Session Resumption

2020-08-30 Thread Tero Kivinen
Paul Wouters writes: > On Fri, 28 Aug 2020, Michael Richardson wrote: > > >> We added a suspend commend, but since that deleted states on the > >> initiator, it ended up sending delete's to the server. The server > >> deleted the IKE SAs. Now the client can resume a connection that > >

Re: [IPsec] Question on RFC 5723 Session Resumption

2020-08-30 Thread Paul Wouters
On Mon, 31 Aug 2020, Tero Kivinen wrote: That should not matter, the server should not invalidate tickets even if there is liveness failures, as if it does that every time there is transient network failure the resumption is useless. I agree, but that is not what the RFC says. Perhaps this wou