Re: Issue 70: Non-SAD updates (was: 51 - spi collisions)
Francis Dupont <[email protected]> Mon, 07 Nov 2005 23:41:46 +0100
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote:
Hmm... actually the text I proposed was not quite right. Using a
single IP address as the sole identifier for the right peer simply
doesn't work correctly, since an IP address does not uniquely identify
a peer (for similar reasons as in issue 51). More likely, it has to
also take into account information in the PAD etc..
=> yes, this is a known issue for ipsec-tools...
How about rephrasing the last paragraph to something like this?
When performing these steps, implementations may use information
contained in the SPD, the PAD, and possibly some other
implementation-specific databases. Regardless of how exactly the
steps are implemented, it is important to remember that IP
addresses can change, and that an IP address alone does not always
uniquely identify a single IKE peer (for the same reasons as why
the combination of the remote IP address and SPI does not uniquely
identify an outbound IPsec SA; see Appendix A.1). Thus, in steps 1
and 2 it may be easier to identify the "right peer" using its
authenticated identity instead of its current IP address. However,
these implementation details are beyond the scope of this
specification.
=> the sentence about the authenticated identity is IMHO only for
positive step 2 but I think the text is enough detailed.
Thanks
[email protected]