Re: Opinions on unresolved CARD issues
Vijay Devarapalli <[email protected]>
| Newsgroups | gmane.ietf.seamoby |
|---|---|
| Message-ID | <[email protected]> |
Singh Ajoy-ASINGH1 wrote: > > 1. Issue #23: Protection of broadcast unsolicited CARD reply messages. A broadcast unsolicted CARD reply message cannot be protected with IPSec, so how are the SAs established? Similar problem to Router Advertisements. If we leave broadcast/multicast to be determined (see issue #6) then this does not need to be solved right now. There is no WG consensus at this time - we need to take this to the list. comments please. > > AJOY-> We have not heard any comments so far. So, We are assuming that this issue need not be addressed by the CARD protocol. Any comments? > > We are assuming that CARD protocol is not required to solve this issue in short term. Any comments? currently you cannot protect broadcast messsages with IPsec. multicast messages could be protected if all the members of the multicast group have the key. so you should probably just mention this in the spec. the spec shouldnt assume unsolicited CARD reply messages will be protected and remain silent. Vijay