Re: [IPsec] Question on RFC 5723 Session Resumption

2020-08-31 Thread Benjamin Kaduk
On Sun, Aug 30, 2020 at 10:42:07PM -0400, Paul Wouters wrote: > On Mon, 31 Aug 2020, Tero Kivinen wrote: > > > That should not matter, the server should not invalidate tickets even > > if there is liveness failures, as if it does that every time there is > > transient network failure the resumptio

Re: [IPsec] Question on RFC 5723 Session Resumption

2020-08-31 Thread Michael Richardson
Tero Kivinen wrote: > Normally the ticket is encrypted with key that is changed every time > the server configuration changes, which means changing the server > configuration will invalidate all tickets. This is probably a rather bad thing. > If this is not wanted for > chan