#27 [*](2401bis) SPD Considerations (section 10.1)
Kazunori Miyazawa <[email protected]> Tue, 08 Feb 2005 16:10:21 +0900
| Newsgroups | gmane.ietf.kink |
|---|---|
| Message-ID | <[email protected]> |
#27 [*](2401bis) SPD Considerations (section 10.1) This should not go in the security considartions section. It is really more about IPsec architectural considerations than security considerations. I agree. I don't think they are security issues. This text needs to take into account 2401bis. In particular it needs to be properly split between SPD considerations and PAD considerations. (Sam Hartman) I think the first paragraph may be kind of message flow or over view of protocol because it specifies condition under which we should use GETTGT or normal key exchange. If KINK refers to 2401bis, I think that almost of section 10.1 is related to PAD rather than SPD, because SPD specifies filtering rules and the way to process in 2401bis. Second paragraph of section 10.1 requires these parameters in SPD 1 KDC to contact 2 principal name for respondent 3 AP-REQ/AP-REP or u2u to CREATE/DELETE However I think only the principal name should be held by PAD, and others (1,3) should be left to implementation, because IPsec stack is not concerned with how to exchange the key. 2401bis says PAD stores shared secret if peer authenticated by the secret. When we apply this to KINK, we might store the ticket into PAD. -- Kazunori Miyazawa