#27 [*](2401bis) SPD Considerations (section 10.1)

Kazunori Miyazawa <[email protected]> Tue, 08 Feb 2005 16:10:21 +0900
Newsgroups gmane.ietf.kink
Message-ID <[email protected]>
#27 [*](2401bis) SPD Considerations (section 10.1)

	This should not go in the security considartions section.  It is
	really more about IPsec architectural considerations than security
	considerations.

I agree. I don't think they are security issues.

	This text needs to take into account 2401bis.  In particular it needs
	to be properly split between SPD considerations and PAD
	considerations.  (Sam Hartman)

I think the first paragraph may be kind of message flow or over view of protocol
because it specifies condition under which we should use GETTGT or normal key
exchange.

If KINK refers to 2401bis, I think that almost of section 10.1 is related to PAD
rather than SPD, because SPD specifies filtering rules and the way to process in
2401bis.

Second paragraph of section 10.1 requires these parameters in SPD
1 KDC to contact
2 principal name for respondent
3 AP-REQ/AP-REP or u2u to CREATE/DELETE

However I think only the principal name should be held by PAD, and others (1,3)
should be left to implementation, because IPsec stack is not concerned with
how to exchange the key.

2401bis says PAD stores shared secret if peer authenticated by the secret.
When we apply this to KINK, we might store the ticket into PAD.

--
Kazunori Miyazawa