Scott C Moonen writes:
> We've interpreted it as follows: 1) the old IKE SA's PRF is used to 
> produce SKEYSEED, but 2) the new IKE SA's PRF is used to produce SK_x.

Hmm... when reading my code, it seems I do the same, but when I read
the text I interpreted it differently, so I think we need some
clarification text there... 
-- 
[email protected]
_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to