Re: Issue 70: Non-SAD updates (was: 51 - spi collisions)

Jari Arkko <[email protected]> Tue, 15 Nov 2005 20:15:15 +0200
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
I'm OK with Pasi's initial suggestion as updated
below in his e-mail.

--Jari

>How about rephrasing the last paragraph to something like this?
>
>   When performing these steps, implementations may use information
>   contained in the SPD, the PAD, and possibly some other
>   implementation-specific databases.  Regardless of how exactly the
>   steps are implemented, it is important to remember that IP
>   addresses can change, and that an IP address alone does not always
>   uniquely identify a single IKE peer (for the same reasons as why
>   the combination of the remote IP address and SPI does not uniquely
>   identify an outbound IPsec SA; see Appendix A.1).  Thus, in steps 1
>   and 2 it may be easier to identify the "right peer" using its
>   authenticated identity instead of its current IP address.  However,
>   these implementation details are beyond the scope of this
>   specification.
>  
>