Re: AD review: draft-ietf-kink-kink [section 1-4]

"KAMADA Ken'ichi" <[email protected]> Fri, 04 Feb 2005 17:04:51 +0900
Newsgroups gmane.ietf.kink
Message-ID <20050204170451BM%[email protected]>
At Tue, 01 Feb 2005 17:06:33 -0500,
Sam Hartman <[email protected]> wrote:
> 
> >>>>> "KAMADA" == KAMADA Ken'ichi <[email protected]> writes:
> 
>     >>  Section 4.3:
>     >> 
>     >> [**] I need explicit review from the IPsec reviewer of this
>     >> section to make sure it is compatible with 2401bis.  IN
>     >> addition, any differences between how this works and how IKE
>     >> would set up the same SA need to be called out.  It is fine for
>     >> there to be differences, but I want to make sure the working
>     >> group explicitly decided the differences are a good thing.
>     >> 
>     >> I'm somewhat concerned that 4.3 is not specific enough to
>     >> describe exactly what key gets set up.  I.E. I'm concerned it
>     >> may not be detailed enough for interoperable implementations.
> 
>     KAMADA> Section 4.3 describes the message flow and section 7.3
>     KAMADA> describes the message structure.  Differences between KINK
>     KAMADA> and IKE is described in section 7.3 (and also in section
>     KAMADA> 4.4.1, 5.1.7, and 6).  I think they are enough to be
>     KAMADA> interoperable (at least regarding SA setup).  Is your
>     KAMADA> concern resolved if section 4 referes to section 7?
> 
> I think everything is clear except for what key ends up getting used
> for the resulting SA.  I think that needs specific text.

The key used for IPsec SAs is defined in section 8, "Key Derivation".
Its definition follows IKEv1.

-- 
KAMADA Ken'ichi <[email protected]>