My draft draft-kivinen-ipsecme-oob-pubkey-02.txt defines new way to
send any type of raw public keys inside IKEv2. RFC5996 only allows
sending RSA raw public keys. This means after this we would have two
ways to do send RSA raw public keys, old RFC5996 and new format define
din my draft.
In yesterdays IPsecME meeting I asked following question about what to
do with the Raw RSA Public Key Type:
1) Make this new format completely optional
Leave old RFC 5996 format as is, both this new format and the
old format can be used. In that case this document can be
informational, and it does not need to updated RFC5996.
2) Make this new format recommended, but keep old format
Leave old RFC 5996 format as is, but make this new format as
preferred format, i.e. add text which says SHOULD use this new
format if it is supported, and SHOULD NOT for old format. Old
format can be used for backward compatibility. In this case
this document should be standard track, and update RFC5996.
3) Obsolete old format
Make old RFC 5996 format as MUST NOT, and officially obsolete
it. This means all implementations should switch to new format
as soon as possible. This document must be standard track, and
update RFC5996.
In the discussion we did not found out that there would have been wide
use for the old RFC 5996 defined RSA raw public key, so feeling was
that it would be possible to obsolete the old format. It was
considered a bad idea to keep two ways of doing same thing.
So now I want to know if anybody have anything against if we do just
that, i.e. pick the 3rd option and obsolete the old RSA raw public key
format.
The another question is whether this document needs to be WG document
or not. As it seems to be that we are updating the RFC5996 and
obsoleting stuff from it, there seemed to be some people who felt that
this should be WG document. Send your comments about this too.
Please send your comments here in the list during the next two weeks
(I will be traveling during the next two weeks, and plan to make
necessary changes (if any) to the draft after I get back to home).
--
[email protected]
_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec