comments on draft-ietf-mobike-protocol-01.txt
Shinta Sugimoto <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Hello, I read draft-ietf-mobike-protocol-01.txt and had following comments/questions. Technical Comments/Questions: - Section 2.3 (Changing addresses in IPsec SAs) I need clarification on how address change functions in MOBIKE. First of all, does UPDATE_SA_ADDRESSES take effect on more than one address changes ? Or it's supposed to update a single address ? Probably I am confusing the purpose of UPDATE_SA_ADDRESSES and ADDITIONAL_*_ADDRESS. In my understanding, UPDATE_SA_ADDRESSES is for updating the preferred address, which means that IKE_SA and IPsec SA (only matched one) are the target of the address update. OTOH, ADDITIONAL_*_ADDRESS is for updating (requesting its peer to update) the peer address set. Do I get it right? One more question: Should the initiator make all the CHILD_SAs inactive which are associated with the IKE_SA whose "pending_update" flag is set ? - Section 2.7 (NAT prevention), I also felt that better naming is needed for NAT_PREVENTED. Taking look at issue #24, I tend to agree that NAT_PREVENTED should be replaced with something like NAT_PREVENTION_FAILURE from which one can easily understand that it's an erroneous state (or failure case). Editorial Comments: - Section 2.3 (Changing addresses in IPsec SAs), 3rd bullet, it says "If there are outstanding IKEv2 requests, continues retransmitting them using the addresses in the IKE_SA (the new addresses)." It is unclear to me what the "outstanding IKEv2 requests" are. - Section 2.4 (Updating additional addresses), the first sentence says "both the initiator and responder can send a list of additional addresses (in addition to the one used for IKE_SA_INIT/IKE_AUTH exchange) to the initiator in the IKE_AUTH exchange." It seems to me that the sentence is a bit paradoxical. IMHO, the phrase "to the initiator" can be eliminated. Regards, Shinta