[IPsec] Re: G-IKEv2 review comments

2024-09-03 Thread Valery Smyslov
HI Tero, > Valery Smyslov writes: > > > I did understand that, but I do not see point of sending extra > > > 8-octets as > > the first 8- > > > octets already identifies the IKE SA... > > > > The point is that we want to re-use IKEv2 header, which contains two > > IKE SPIs. > > Sure, but this doe

[IPsec] Re: G-IKEv2 review comments

2024-09-03 Thread Tero Kivinen
Valery Smyslov writes: > > > In normal IKEv2 each side selects its own IKE SPI, but in > > > G-IKEv2 it is impossible. It is the GCKS that provides GMs with SPI > > > for rekey SA and GMs will have to use it to select the right SA. > > > > Yes, but as the GM will always only use the first 8 octets