Re: Scope of SA change in design document..

Francis Dupont <[email protected]> Mon, 14 Nov 2005 11:48:50 +0100
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   Actually that is not problem with issue 8. The issue 8 is about moving
   only part of SAs created between two hosts. One SA always will use
   exactly one address pair regardless of issue 8. Our charter do rule
   out load balancing, i.e. using multiple addresses at the same time for
   single IPsec SA is explicitly ruled out for the group.
   
=> so we agree the issue 8 is not out of the charter.

   We do already offer a way for the host to create separate group of SAs
   which are moved separately from each other, i.e. applications can
   create multiple IKE SAs, and create the IPsec SAs to the IKE SA having

=> this, to have to create multiple IKE SAs between the same peers,
is exactly we'd like to change (including in Monami6 WG concern).

   similar IPsec SAs. I.e. if you have 3 different groups of IPsec SAs
   wanting to have different charasteristics from the interfaces uses,
   you can create 3 IKE SAs and create those IPsec SAs inside each of
   those IKE SAs. Then you have 3 groups (IKE SAs) which you can
   separately move from one address pair to another.
   
Regards

[email protected]

PS: note there are at most two issues to solve to support this:
 - choose between either sending the message using the "new" address
   or adding a new field for the "new" address.
   (the first is a simplest extension of the current style).
 - a place to put the list of SAs to update.
For the second IMHO an update payload is better.