Re: TS updates in MOBIKE
"Narayanan, Vidya" <[email protected]> Fri, 2 Nov 2007 10:43:03 -0700
| Newsgroups | gmane.ietf.mobike,gmane.ietf.ipsec |
|---|---|
| Message-ID | <[email protected]> |
Hi Jari, > -----Original Message----- > From: Jari Arkko [mailto:[email protected]] > Sent: Thursday, November 01, 2007 10:26 PM > To: Narayanan, Vidya > Cc: [email protected]; [email protected] > Subject: Re: [Mobike] TS updates in MOBIKE > > Presumably because MOBIKE is a mobility and multihoming > facility for IPsec clients and gateways, i.e., you can change > the outer IP addresses. Its not a general SA renegotiation facility. > Yes, I understand that that is the purpose of MOBIKE. But, I don't see a good reason to prevent other updates from happening as part of that same exchange. For e.g., let's say that when my address changes, I want to update the SA (or rekey) to start encrypting some additional traffic (fitting different selector criteria) using the same SA - the initiator now has to do separate MOBIKE and rekeying exchanges, which is not really efficient. > Yes, it could be done, but I'm not sure that's really within > the scope of the feature. Unless we are talking about > extension to deal with transport mode, which has been > something at least a few people were interested in. > I think the above point of updating the SAs applies equally to transport and tunnel mode, but, extending MOBIKE for transport mode is independently useful in my view. Regards, Vidya > Jari > > Narayanan, Vidya kirjoitti: > > Hi, > > RFC4555 only allows updates to tunnel endpoint addresses and not > > selectors, etc. Does anyone know why TS updates are not > permitted? > > If MOBIKE allowed what an SA rekey would allow, what is the problem? > > > > Thanks, > > Vidya > > _______________________________________________ > > Mobike mailing list > > [email protected] > > https://www.machshav.com/mailman/listinfo.cgi/mobike > > > > > > >