RE: : FW: IPSec use with Diameter (from the IPSEC WG list)

<[email protected]>
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
Hi Jari & Bernard,

> > John, do you remember why we put it in this
> > text?

This was written, by Bernard and:

> I don't believe that the text is incorrect.
> 
> While the IKEv1 initiator may know what port the phase I SA is intending
> to protect, the responder cannot know this because that information is not
> included in the IKEv1 phase 1 exchange.  It doesn't matter how many phase
> 1 SAs are brought up between the two endpoints.  The responder has no idea
> what the phase 1 SA is being brought up for, and so is unable to enforce
> different certificate policies based on the (undisclosed) application.
> 
> In phase 2 the information is available, but by then it's too late.

As I remember, this was the point of the text, so I also don't think that the
text is incorrect.

John
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.