Re: [IPsec] WGLC for draft-ietf-ipsecme-ikev2-multiple-ke

2021-08-23 Thread Valery Smyslov
Hi Paul, > On Fri, 30 Jul 2021, Valery Smyslov wrote: > > [ replying as I got prompted by Tero on this regarding WGLC ] > > >> I have reviewed the document. In general I support this document. I > >> really like the idea of renaming the DH Registry to KE. I do think it > >> is not ready yet thou

Re: [IPsec] WGLC for draft-ietf-ipsecme-ikev2-multiple-ke

2021-08-20 Thread CJ Tjhai
On Mon, 16 Aug 2021 at 21:24, Paul Wouters wrote: > On Fri, 30 Jul 2021, Valery Smyslov wrote: > > [ replying as I got prompted by Tero on this regarding WGLC ] > > >> I have reviewed the document. In general I support this document. I > >> really like the idea of renaming the DH Registry to KE.

Re: [IPsec] WGLC for draft-ietf-ipsecme-ikev2-multiple-ke

2021-08-16 Thread Paul Wouters
On Fri, 30 Jul 2021, Valery Smyslov wrote: [ replying as I got prompted by Tero on this regarding WGLC ] I have reviewed the document. In general I support this document. I really like the idea of renaming the DH Registry to KE. I do think it is not ready yet though. My comments and questions f

[IPsec] WGLC for draft-ietf-ipsecme-ikev2-multiple-ke

2021-08-16 Thread Tero Kivinen
Tero Kivinen writes: > This is the start of 2 week WGLC on the > draft-ietf-ipsecme-ikev2-multiple-ke document, ending 2021-08-10. > > Please submit your comments to the list, also send a note if you have > reviewed the document, so we can see how many people are interested in > getting this out.

Re: [IPsec] WGLC for draft-ietf-ipsecme-ikev2-multiple-ke

2021-08-10 Thread CJ Tjhai
Hi Rebecca, The draft document aims to be as generic as possible, treating the KE payload as opaque. It should cater for cases such as: - multiple key exchanges involving more than one (EC)DH groups (perhaps due to policy requirements); - combinations of (EC)DH and KEM; - KEM only, either single o

Re: [IPsec] WGLC for draft-ietf-ipsecme-ikev2-multiple-ke

2021-07-30 Thread Valery Smyslov
Hi Paul, thank you for the review. Please find my comments inline. > > This is the start of 2 week WGLC on the > > draft-ietf-ipsecme-ikev2-multiple-ke document, ending 2021-08-10. > > Note that this document has a prerequisite on the intermediate exchange, > so even if it passed WGLC/IETF LC be

Re: [IPsec] WGLC for draft-ietf-ipsecme-ikev2-multiple-ke

2021-07-28 Thread Tobias Brunner
Hi Paul, Trying to clarify some things from my experience implementing this extension. The authors might have some more insights on these points. Key exchange methods negotiated via Transform Type 4 MUST always take place in the IKE_SA_INIT exchange. Additional key exchanges

Re: [IPsec] WGLC for draft-ietf-ipsecme-ikev2-multiple-ke

2021-07-27 Thread Paul Wouters
On Tue, 27 Jul 2021, Tero Kivinen wrote: Subject: [IPsec] WGLC for draft-ietf-ipsecme-ikev2-multiple-ke This is the start of 2 week WGLC on the draft-ietf-ipsecme-ikev2-multiple-ke document, ending 2021-08-10. Note that this document has a prerequisite on the intermediate exchange, so even

[IPsec] WGLC for draft-ietf-ipsecme-ikev2-multiple-ke

2021-07-26 Thread Tero Kivinen
This is the start of 2 week WGLC on the draft-ietf-ipsecme-ikev2-multiple-ke document, ending 2021-08-10. Please submit your comments to the list, also send a note if you have reviewed the document, so we can see how many people are interested in getting this out. -- kivi...@iki.fi _