Re: #29 [*](2401bis) Rekeying (section 4.4.1)

Kazunori Miyazawa <[email protected]> Fri, 18 Feb 2005 11:43:40 +0900
Newsgroups gmane.ietf.kink
Message-ID <[email protected]>
Bill Sommerfeld wrote:
> On Tue, 2005-02-15 at 02:07, Kazunori Miyazawa wrote:
> 
> 
>>Normally a KINK implementation which rekeys existing security associations will
>>start to rekey the security association at the soft lifetime. In order to avoid
>>synchronization with similar implementations, KINK initiators MUST randomly pick
>>a rekeying time between the soft lifetime and the hard lifetime minus the amount
>>of time it would take to go through a full retransmission time cycle, Tretrans.
>>The soft lifetime SHOULD be set at least twice Tretrans before the hard lifetime.
> 
> 
> Another way to phrase this: "the soft lifetime must be randomized to avoid synchronization.."
> 


At first, I assumed that a soft lifetime of a SA might be sat by an administrator.

But the lifetime negotiation affects only the hard lifetime and an entity which 
supports KINK protocol probably has rights to determine the soft lifetime.
I think your phrase is better because of simplicity.

Should we describe a limits of the randomization?
I think it may be an implementation issue.

--
Kazunori Miyazawa