Re: #29 [*](2401bis) Rekeying (section 4.4.1)
Kazunori Miyazawa <[email protected]> Fri, 18 Feb 2005 11:43:40 +0900
| Newsgroups | gmane.ietf.kink |
|---|---|
| Message-ID | <[email protected]> |
Bill Sommerfeld wrote: > On Tue, 2005-02-15 at 02:07, Kazunori Miyazawa wrote: > > >>Normally a KINK implementation which rekeys existing security associations will >>start to rekey the security association at the soft lifetime. In order to avoid >>synchronization with similar implementations, KINK initiators MUST randomly pick >>a rekeying time between the soft lifetime and the hard lifetime minus the amount >>of time it would take to go through a full retransmission time cycle, Tretrans. >>The soft lifetime SHOULD be set at least twice Tretrans before the hard lifetime. > > > Another way to phrase this: "the soft lifetime must be randomized to avoid synchronization.." > At first, I assumed that a soft lifetime of a SA might be sat by an administrator. But the lifetime negotiation affects only the hard lifetime and an entity which supports KINK protocol probably has rights to determine the soft lifetime. I think your phrase is better because of simplicity. Should we describe a limits of the randomization? I think it may be an implementation issue. -- Kazunori Miyazawa