Re: AD review: draft-ietf-kink-kink [section 1-4]
"KAMADA Ken'ichi" <[email protected]> Fri, 04 Feb 2005 17:04:51 +0900
| Newsgroups | gmane.ietf.kink |
|---|---|
| Message-ID | <20050204170451BM%[email protected]> |
At Tue, 01 Feb 2005 17:06:33 -0500, Sam Hartman <[email protected]> wrote: > > >>>>> "KAMADA" == KAMADA Ken'ichi <[email protected]> writes: > > >> Section 4.3: > >> > >> [**] I need explicit review from the IPsec reviewer of this > >> section to make sure it is compatible with 2401bis. IN > >> addition, any differences between how this works and how IKE > >> would set up the same SA need to be called out. It is fine for > >> there to be differences, but I want to make sure the working > >> group explicitly decided the differences are a good thing. > >> > >> I'm somewhat concerned that 4.3 is not specific enough to > >> describe exactly what key gets set up. I.E. I'm concerned it > >> may not be detailed enough for interoperable implementations. > > KAMADA> Section 4.3 describes the message flow and section 7.3 > KAMADA> describes the message structure. Differences between KINK > KAMADA> and IKE is described in section 7.3 (and also in section > KAMADA> 4.4.1, 5.1.7, and 6). I think they are enough to be > KAMADA> interoperable (at least regarding SA setup). Is your > KAMADA> concern resolved if section 4 referes to section 7? > > I think everything is clear except for what key ends up getting used > for the resulting SA. I think that needs specific text. The key used for IPsec SAs is defined in section 8, "Key Derivation". Its definition follows IKEv1. -- KAMADA Ken'ichi <[email protected]>