Jari, > But the modifications necessary before ESP works well > enough for ND are pretty interesting. The basic problem > we need to deal with manually keyed ESP is dst address > as a pointer to the SA; this needs to change if manual > keying is to be used. Another basic problem is inability > to use *any* IP-based key management protocol (including > IKE) due to chicken-and-egg effect. A third problem
Actually PANA should be able to work before IP address configuration, and most possibly (not a requirement) will distribute keys... > is that when the ND protection gets host specific - > as it should - we need some way of indicating individual > SAs. alper -------------------------------------------------------------------- IETF IPng Working Group Mailing List IPng Home Page: http://playground.sun.com/ipng FTP archive: ftp://playground.sun.com/pub/ipng Direct all administrative requests to [EMAIL PROTECTED] --------------------------------------------------------------------
