Jari,

> But the modifications necessary before ESP works well
> enough for ND are pretty interesting. The basic problem
> we need to deal with manually keyed ESP is dst address
> as a pointer to the SA; this needs to change if manual
> keying is to be used. Another basic problem is inability
> to use *any* IP-based key management protocol (including
> IKE) due to chicken-and-egg effect. A third problem

Actually PANA should be able to work before IP address
configuration, and most possibly (not a requirement) will
distribute keys... 


> is that when the ND protection gets host specific -
> as it should - we need some way of indicating individual
> SAs.


alper

--------------------------------------------------------------------
IETF IPng Working Group Mailing List
IPng Home Page:                      http://playground.sun.com/ipng
FTP archive:                      ftp://playground.sun.com/pub/ipng
Direct all administrative requests to [EMAIL PROTECTED]
--------------------------------------------------------------------

Reply via email to