The following errata report has been submitted for RFC9370,
"Multiple Key Exchanges in the Internet Key Exchange Protocol Version 2 (IKEv2)"

--------------------------------------
You may review the report below and at:
https://errata.rfc-editor.org/eid9036/

--------------------------------------
Type: Technical
Reported by: Andrew Cagney <[email protected]>

Section 2.2.4-5 says:

Original Text
-------------
The responder MUST include this notification in a CREATE_CHILD_SA or 
IKE_FOLLOWUP_KE response message in case the next IKE_FOLLOWUP_KE exchange is 
expected, filling it with some data that would allow linking the current 
exchange to the next one. The initiator MUST send back this notification intact 
in the request message of the next IKE_FOLLOWUP_KE exchange.

Corrected Text
--------------
Suspect the text was meant to say something like:

  The responder MUST include this notification in a CREATE_CHILD_SA or 
IKE_FOLLOWUP_KE response message in the case of a further IKE_FOLLOWUP_KE 
exchange is expected, ...

But better text would something like:

 The responder MUST include this notification in the CREATE_CHILD_SA response 
message, and in all but the final IKE_FOLLOWUP_KE response message, ...

Notes
-----
To my reading, the current sentence states that an ADDITIONAL_KEY_EXCHANGE 
notification payload MUST be included in all IKE_FOLLOW_UP response messages, 
just "in case" a further IKE_FOLLOW_UP exchange is needed (we're not sure so 
we're hedging our bets).

Instructions:
-------------
This erratum is currently posted as "Reported". Please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party  
will log in to change the status and edit the report, if necessary.

--------------------------------------
RFC9370 (draft-ietf-ipsecme-ikev2-multiple-ke)
--------------------------------------
Title               : Multiple Key Exchanges in the Internet Key Exchange 
Protocol Version 2 (IKEv2)
Publication Date    : May 2023
Author(s)           : CJ. Tjhai, M. Tomlinson, G. Bartlett, S. Fluhrer, D. Van 
Geest, O. Garcia-Morchon, V. Smyslov
Category            : Proposed Standard
Source              : ipsecme (sec)
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to