issue-#46: Failure indication in a trusted-anchor sub-option

"James Kempf" <[email protected]> Wed, 5 May 2004 12:03:51 -0700
Newsgroups gmane.ietf.seamoby
Message-ID <[email protected]>
(Breaking the reply to Marco up into seperate emails for each issue...)

The issue is that the RESOLVER_ERROR indication is only meant to apply to
the L2-ID resolution, and draft 07 also uses it to indicate that a trusted
anchor suboption did not match any anchor certificate.

One suggested solution was to return the Trusted Anchor suboption in the
reply if there is an error, the other was to set a flag in the CARD Reply
header if an error occurs.

The suggested resolution is to return the Trusted Anchor suboption.

The suggested text changes are the following:

Replace the following sentence in Section 4 paragraph 5:

"The MN includes in the CARD Request message a list of trusted anchors for
which the MN has a certificate and the AR replies with the certificate
chain, or with a RESOLOVER ERROR if no match is found for any of the trusted
anchors."

with:

"The MN includes in the CARD Request message a list of trusted anchors for
which the MN has a certificate and the AR replies with the certificate
chain. If no match is found, the AR returns the trusted anchor in the reply"

Replace the following sentence in Section 6.4 paragraph 2:

"The AR replies by sending a CARD Reply containing an Address sub-option for
itself and the Router Certificate sub-options (Section 5.1.3.7) containing
its certificate chain matching one of the requested trust anchors. If the
trusted anchor option does not match any certificate, the AR returns the
Trusted Anchor option in the reply."

            jak