Re: [IPsec] Question on RFC 5723 Session Resumption

2020-09-01 Thread Paul Wouters
On Mon, 31 Aug 2020, Michael Richardson wrote: Tero Kivinen wrote: > Normally the ticket is encrypted with key that is changed every time > the server configuration changes, which means changing the server > configuration will invalidate all tickets. This is probably a rather bad thin

Re: [IPsec] Question on RFC 5723 Session Resumption

2020-09-01 Thread Tero Kivinen
Paul Wouters writes: > On Mon, 31 Aug 2020, Tero Kivinen wrote: > > > That should not matter, the server should not invalidate tickets even > > if there is liveness failures, as if it does that every time there is > > transient network failure the resumption is useless. > > I agree, but that is n

Re: [IPsec] Question on RFC 5723 Session Resumption

2020-09-01 Thread Tero Kivinen
Michael Richardson writes: > > Tero Kivinen wrote: > > Normally the ticket is encrypted with key that is changed every time > > the server configuration changes, which means changing the server > > configuration will invalidate all tickets. > > This is probably a rather bad thing. I