Re: [IPsec] Question on RFC 5723 Session Resumption

2020-09-03 Thread Valery Smyslov
Hi Paul, > So here is my first pass: > > Abstract: > > Current: > > A client can reconnect to a gateway from which it was disconnected. > > New: > > A client can reconnect to a gateway from which it was disconnected, > due to a network issue between the client and server. I don't

Re: [IPsec] Question on RFC 5723 Session Resumption

2020-09-03 Thread Paul Wouters
On Thu, 3 Sep 2020, Valery Smyslov wrote: Current: A client can reconnect to a gateway from which it was disconnected. New: A client can reconnect to a gateway from which it was disconnected, due to a network issue between the client and server. I don't like this change - it's t

Re: [IPsec] Question on RFC 5723 Session Resumption

2020-09-03 Thread Valery Smyslov
Hi Paul, > >> Section 6.2: > >> > >> Current: > >> > >> Each ticket is associated with a single IKE SA. In particular, when > >> an IKE SA is deleted by the client or the gateway, the client MUST > >> delete its stored ticket. Similarly, when credentials associated > >> with the

Re: [IPsec] Question on RFC 5723 Session Resumption

2020-09-03 Thread Tero Kivinen
By first look the changes seemed way too big for errata, but it seems they are getting narrowed down to something that could be actually done by errata. If we want to do something bigger we can of course do 5723bis and do other things at the same time if needed. Paul Wouters writes: > > The fol