Re: Issue 70: Non-SAD updates (was: 51 - spi collisions)

Francis Dupont <[email protected]> Mon, 07 Nov 2005 23:41:46 +0100
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   Hmm... actually the text I proposed was not quite right. Using a
   single IP address as the sole identifier for the right peer simply
   doesn't work correctly, since an IP address does not uniquely identify
   a peer (for similar reasons as in issue 51).  More likely, it has to
   also take into account information in the PAD etc..
   
=> yes, this is a known issue for ipsec-tools...

   How about rephrasing the last paragraph to something like this?
   
      When performing these steps, implementations may use information
      contained in the SPD, the PAD, and possibly some other
      implementation-specific databases.  Regardless of how exactly the
      steps are implemented, it is important to remember that IP
      addresses can change, and that an IP address alone does not always
      uniquely identify a single IKE peer (for the same reasons as why
      the combination of the remote IP address and SPI does not uniquely
      identify an outbound IPsec SA; see Appendix A.1).  Thus, in steps 1
      and 2 it may be easier to identify the "right peer" using its
      authenticated identity instead of its current IP address.  However,
      these implementation details are beyond the scope of this
      specification.
     
=> the sentence about the authenticated identity is IMHO only for
positive step 2 but I think the text is enough detailed.

Thanks

[email protected]