Re: [secdir] Review of draft-manral-ipsec-rfc4305-bis-errata-02.txt

Nicolas Williams <Nicolas.Williams@sun.com> Wed, 13 December 2006 13:02 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1GuTkT-0004LE-42; Wed, 13 Dec 2006 08:02:13 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1GuTkR-0004Kj-R4; Wed, 13 Dec 2006 08:02:11 -0500
Received: from brmea-mail-2.sun.com ([192.18.98.43]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1GuTkM-00055O-Mu; Wed, 13 Dec 2006 08:02:11 -0500
Received: from centralmail4brm.central.Sun.COM ([129.147.62.198]) by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id kBDD26MD006034; Wed, 13 Dec 2006 06:02:06 -0700 (MST)
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104]) by centralmail4brm.central.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL, v2.2) with ESMTP id kBDD25nU004926; Wed, 13 Dec 2006 06:02:06 -0700 (MST)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1]) by binky.Central.Sun.COM (8.13.6+Sun/8.13.6) with ESMTP id kBDD200X009885; Wed, 13 Dec 2006 07:02:00 -0600 (CST)
Received: (from nw141292@localhost) by binky.Central.Sun.COM (8.13.6+Sun/8.13.6/Submit) id kBDD1xFD009884; Wed, 13 Dec 2006 07:01:59 -0600 (CST)
Date: Wed, 13 Dec 2006 07:01:59 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Vishwas Manral <vishwas@ipinfusion.com>
Message-ID: <20061213130158.GG26175@binky.Central.Sun.COM>
References: <20061211155532.GB26832@binky.Central.Sun.COM> <457DC1E2.30206@ipinfusion.com> <20061211211932.GA26175@binky.Central.Sun.COM> <7.0.0.16.2.20061211172844.042844d8@vigilsec.com> <20061211223453.GE26175@binky.Central.Sun.COM> <3964E240930ED1BB542312EA@sirius.fac.cs.cmu.edu> <20061212230633.GD26175@binky.Central.Sun.COM> <457F3D80.8020902@ipinfusion.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <457F3D80.8020902@ipinfusion.com>
User-Agent: Mutt/1.5.7i
X-Spam-Score: 0.0 (/)
X-Scan-Signature: d6b246023072368de71562c0ab503126
Cc: ietf@ietf.org, secdir@mit.edu, iesg@ietf.org, Jeffrey Hutzelman <jhutz@cmu.edu>
Subject: Re: [secdir] Review of draft-manral-ipsec-rfc4305-bis-errata-02.txt
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
Errors-To: ietf-bounces@ietf.org

On Tue, Dec 12, 2006 at 03:38:40PM -0800, Vishwas Manral wrote:
> Hi Nico,
> 
> I guess there is no denying the points that have been put forward about 
> the use of NULL both authentication and encryption algorithms for ESP in 
> debugging.
> 
> RFC4301 already clearly states:
> 
>   Note: A compliant implementation MUST NOT allow instantiation of an
>   ESP SA that employs both NULL encryption and no integrity algorithm.

Ah.  Then just add reference to RFC4301, section 4.2, in parenthesis.
That should sufifce.

Thanks,

Nico
-- 

_______________________________________________
Ietf mailing list
Ietf@ietf.org
https://www1.ietf.org/mailman/listinfo/ietf