Re: [IPsec] Proposed method to achieve quantum resistant IKEv2

2017-08-05 Thread Cen Jung Tjhai
Hi Paul, >>> 4. The large quantum resistant ‘blob’ of data is only sent when it is >>> known that the peer will accept this. >>I don't understand this? You mean known by preconfiguration? That would >>make migration really difficult and introduce a flag day. It would also >>not be true for

Re: [IPsec] Proposed method to achieve quantum resistant IKEv2

2017-08-05 Thread Cen Jung Tjhai
​Hi Valery,   >>And I think if the IKE_SA_INIT messages grow too large with QSKE, then it’s >>better to develop >>generic fragmentation mechanism for IKE_SA_INIT, rather than making it >>specific for fragmenting >>QSKE blobs. Generic mechanism would allow to reuse it in case we’ll have to >>incl