[IPsec] Fwd: I-D Action: draft-nir-ipsecme-cafr-00.txt

Yoav Nir <ynir@checkpoint.com> Tue, 13 August 2013 20:30 UTC

Return-Path: <ynir@checkpoint.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 47D3E11E81C0 for <ipsec@ietfa.amsl.com>; Tue, 13 Aug 2013 13:30:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level:
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tiXtYuAChznt for <ipsec@ietfa.amsl.com>; Tue, 13 Aug 2013 13:29:58 -0700 (PDT)
Received: from smtp.checkpoint.com (smtp.checkpoint.com [194.29.34.68]) by ietfa.amsl.com (Postfix) with ESMTP id 29C6211E81B7 for <ipsec@ietf.org>; Tue, 13 Aug 2013 13:29:57 -0700 (PDT)
Received: from DAG-EX10.ad.checkpoint.com ([194.29.34.150]) by smtp.checkpoint.com (8.13.8/8.13.8) with ESMTP id r7DKTunX006635 for <ipsec@ietf.org>; Tue, 13 Aug 2013 23:29:56 +0300
X-CheckPoint: {520A9744-0-1B221DC2-1FFFF}
Received: from IL-EX10.ad.checkpoint.com ([169.254.2.105]) by DAG-EX10.ad.checkpoint.com ([169.254.3.223]) with mapi id 14.02.0342.003; Tue, 13 Aug 2013 23:29:55 +0300
From: Yoav Nir <ynir@checkpoint.com>
To: "<ipsec@ietf.org> WG" <ipsec@ietf.org>
Thread-Topic: I-D Action: draft-nir-ipsecme-cafr-00.txt
Thread-Index: AQHOl6wRkkEDfWWeVUauNy8L9JO2Ag==
Date: Tue, 13 Aug 2013 20:30:01 +0000
Message-ID: <482E5FF2-2AD7-469B-9679-A5945E609A5F@checkpoint.com>
References: <20130812223310.2768.80108.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [172.31.21.178]
x-kse-antivirus-interceptor-info: scan successful
x-kse-antivirus-info: Clean
x-cpdlp: 112eabf7d433a5e03b75d1bbf118b8a74b00a07491
Content-Type: text/plain; charset="us-ascii"
Content-ID: <D8EB86B55422D74A9E3FAF2275CA28CB@ad.checkpoint.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: [IPsec] Fwd: I-D Action: draft-nir-ipsecme-cafr-00.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipsec>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Aug 2013 20:30:03 -0000

Hi all

For a long time I've felt that re-authentication in IKEv2 has some harsh side effects in both uninterrupted IPsec and in continuation of the internal IP address assignment.

This draft attempts  to solve these issues.

Comments are welcome, and I will be glad if the WG agrees to discuss and adopt this.

Thanks

Yoav

> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> 
> 
> 	Title           : Adopting Child SAs Following Re-Authentication in IKEv2
> 	Author(s)       : Yoav Nir
> 	Filename        : draft-nir-ipsecme-cafr-00.txt
> 	Pages           : 8
> 	Date            : 2013-08-12
> 
> Abstract:
>   This document describes an extension to the IKEv2 protocol whereby
>   Child SAs are moved to the new IKE SA following re-authentication.
>   This allows for a smoother transition with no loss of connectivity.
> 
> 
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-nir-ipsecme-cafr
> 
> There's also a htmlized version available at:
> http://tools.ietf.org/html/draft-nir-ipsecme-cafr-00
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/