The following errata report has been submitted for RFC9370, "Multiple Key Exchanges in the Internet Key Exchange Protocol Version 2 (IKEv2)"
-------------------------------------- You may review the report below and at: https://errata.rfc-editor.org/eid9036/ -------------------------------------- Type: Technical Reported by: Andrew Cagney <[email protected]> Section 2.2.4-5 says: Original Text ------------- The responder MUST include this notification in a CREATE_CHILD_SA or IKE_FOLLOWUP_KE response message in case the next IKE_FOLLOWUP_KE exchange is expected, filling it with some data that would allow linking the current exchange to the next one. The initiator MUST send back this notification intact in the request message of the next IKE_FOLLOWUP_KE exchange. Corrected Text -------------- Suspect the text was meant to say something like: The responder MUST include this notification in a CREATE_CHILD_SA or IKE_FOLLOWUP_KE response message in the case of a further IKE_FOLLOWUP_KE exchange is expected, ... But better text would something like: The responder MUST include this notification in the CREATE_CHILD_SA response message, and in all but the final IKE_FOLLOWUP_KE response message, ... Notes ----- To my reading, the current sentence states that an ADDITIONAL_KEY_EXCHANGE notification payload MUST be included in all IKE_FOLLOW_UP response messages, just "in case" a further IKE_FOLLOW_UP exchange is needed (we're not sure so we're hedging our bets). Instructions: ------------- This erratum is currently posted as "Reported". Please use "Reply All" to discuss whether it should be verified or rejected. When a decision is reached, the verifying party will log in to change the status and edit the report, if necessary. -------------------------------------- RFC9370 (draft-ietf-ipsecme-ikev2-multiple-ke) -------------------------------------- Title : Multiple Key Exchanges in the Internet Key Exchange Protocol Version 2 (IKEv2) Publication Date : May 2023 Author(s) : CJ. Tjhai, M. Tomlinson, G. Bartlett, S. Fluhrer, D. Van Geest, O. Garcia-Morchon, V. Smyslov Category : Proposed Standard Source : ipsecme (sec) Stream : IETF Verifying Party : IESG _______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
