Re: [IPsec] Éric Vyncke's No Objection on draft-ietf-ipsecme-ikev2-multiple-ke-10: (with COMMENT)

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Tue, 29 November 2022 21:55 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B0D8C1524BE; Tue, 29 Nov 2022 13:55:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.598
X-Spam-Level:
X-Spam-Status: No, score=-9.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=cI0Z2knf; dkim=pass (1024-bit key) header.d=cisco.com header.b=SDy+Emsm
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GIuDhNMtSZmK; Tue, 29 Nov 2022 13:54:57 -0800 (PST)
Received: from alln-iport-6.cisco.com (alln-iport-6.cisco.com [173.37.142.93]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5ADD4C14CEEA; Tue, 29 Nov 2022 13:54:57 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=8338; q=dns/txt; s=iport; t=1669758897; x=1670968497; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=uxyYmtGONdkG9yoafsGunpByX8juviwPbB/qPjGu8EE=; b=cI0Z2knfsIGblpWDb8BdlTCP4ZrsSLBjaHWNS/zTAe3jp19ZBrqVn/yw zmnDz+EC0fQCUeZdR8DsZPDB3EkTqvqvQl+xktE27Y60EFu0s3W8SzuYT nL2+0hCdB4950sr+DGE4Inifa2ebbuPUbsAVmZAx06KK8CAwpA0oS/cKN U=;
X-IPAS-Result: A0AnAAC6foZjmIMNJK1aHAEBAQEBAQcBARIBAQQEAQFAgTsHAQELAYFaUoECAlk6RYROg0wDhFBfhXiCJQOBKY9Yhk6EOYEsFIERA0IUDwEBAQ0BATsJBAEBhQUCFoRzAiU0CQ4BAgQBAQEBAwIDAQEBAQEBAwEBBQEBAQIBBwQUAQEBAQEBAQEeGQUOECeFaA2GUwEBAQECARIREQwBATcBCwQCAQgOAwQBAQMCIwMCAgIwFAEFAwgCBAENBRYMglsBgn8jAwEPonQBgT8Cih96gTKBAYIIAQEGBASBOAEDAgELAgJAAZ0OAwaBFCwBhzR0XoMuO4QnJxyBSUSBFScMEIFmgQE+gmIBAQOBKAESASEXg0A5gi6MJoJ8hnEcNwMZKx1AAws7MgpDNwgGElErHBsHgQwqKBUDBAQDAgYTAyACDSgxFAQpEw0rJ28JAgMhZQUDAwQoLAMJIR8HFREmPAdWOgEEAwIPIDgGAwkDAiJUcQIuERUFAwsVJQgFSwQIOQUGUxICChEDEg8GJkYOSD45FgYnQgEwDg4TA12BaQQzgXEKMS+XP2OBPy4tBxZNBCEBGQgICBQOLisEGRxOEQIXDwI6A5InCoMSRphHk20Kg2mLUY8EhgMELoN4jFWGZ5EHXoVxkUYgjSOUdwgLDYR1AgQCBAUCDgEBBjWBLTprcHAVZQGCCAEBATFSGQ+OIBkegzuFFIVKdTsCAQYBCgEBAwkBgjqHZAEB
IronPort-PHdr: A9a23:XjJpIRK7nNBVlEXW0NmcuWEyDhhOgF28FgIW659yjbVIf+zj+pn5J 0XQ6L1ri0OBRoTU7f9Iyo+0+6DtUGAN+9CN5XYFdpEfWxoMk85DmQsmDYaMAlH6K/i/aSs8E YxCWVZp8mv9P1JSHZP1ZkbZpTu56jtBcig=
IronPort-Data: A9a23:UA3IDagqKelIYmZB+XGgFzWkX1616BAKZh0ujC45NGQN5FlHY01je htvD2GHa/yNZDT0ctEgbI+//U1V78PUmIJkSVBp/Ho3QiljpJueD7x1DKtf0wB+jyHnZBg6h ynLQoCYdKjYdleF+lH1dOKJQUBUjclkfJKkYAL/En03FFEMpBsJ00o5wbdg2N8w37BVPivU0 T/Mi5yHULOa82Yc3lI8s8pvfzs24ZweEBtB1rAPTagjUG32zhH5P7pDTU2FFEYUd6EPdgKMq 0kv+5nilo/R109F5tpICd8XeGVSKlLZFVDmZna7x8FOjzAazhHe3JrXO9JNQlxPm2/Uwuot5 9NjlM3oUAQJMLf1zbF1vxlwS0mSPIVP/LvBZHO4q8HWlgvNcmDnxLNlC0Re0Y8wo7ksRzoQs 6VDbmlWN3hvhMruqF6/YuRyl8IoL8TDN4IEsXYmxjbcZRojacmSH/mUu4YDtNs2rp9CObHlN uAVUiBMVAb7ORcQK3U+FY1ryY9EgVGmI2EH9zp5v5Ef7GnT5AVp1rnmdtzYZrSiTsVchEKZq 3ru9GP8GgwGOcbZziCKmlqvh/HOmy79cIMRFfu295ZCgUWIy2c7CRAKWx28u/bRok+mQN9UL kFR8SonrLIp3E2mUte7WAe3yFaIpBcSR59RHvE0rQCV0aff5gvcB2sJUGQEbcEiqM4uQTFv1 VKhnt71C3poqrL9YXOQ7bi8rD6uN24SN2BqTTQaRA0t7t39oZp1lA+nczp4OKexituwEjbqz nXT6iM/nL4Uy8UM0s1X4GwrnRr9jYPRXlRouz+LcWSLz1IhfY2FaZaRvA2zAel7EK6VSVyIv X4hkseY7fwTAZzlqMBraLhTdF1Oz6vYWAAwkWKDDLF6rG30pCDLkZR4pWAgehg4a67obBezO CfuVRVtCIi/1ZdARYZzZ4+3YyjB5fe9TY2+Phw4gyYnX3ScXAaD+CcrbkmK0iW01kMtiqo4f 5ycdK5A7Er264w6nVJapM9EjtfHIxzSI0uIHPgXKDz8iNKjiIa9E+ttDbd3RrlRAFm4iAvU6 c1DEMCB1g9SVubzCgGOr9BCcgxUcyJqXciqwyCySgJlClc3cI3GI6KBqY7Nh6Q+90iovr6Sp yrkChMwJKTX3CWXeW1mlUyPmJu2Dcog8hrXzAQnPE2j3DA4cJ2z4aIEH6bbjpF5nNGPOcVcF qFfE+3ZW6wnYm2ep1w1M8KnxKQ8L0vDuO57F3f/CNTJV8Q+F1WhFx6NVlaHyRTi+QLs7JVh/ ez/j1+LKXfBLiw7ZPvrhDuU5wvZlRAgdChaBiMk/vE7lJ3QzbVX
IronPort-HdrOrdr: A9a23:QKAaHKNoSC8EdsBcT2P155DYdb4zR+YMi2TDiHoedfUFSKOlfp 6V8MjzjSWE9Ar4WBkb6LS90DHpewKSyXcH2/hvAV7EZniphILIFvAv0WKG+Vzd8kLFh5ZgPM tbAspD4ZjLfCVHZKXBkUiF+rQbsaK6GcmT7I+0pRoMPGJXguNbnn1E422gYypLrXx9dOME/e 2nl6x6TlSbCBEqR/X+IkNAc/nIptXNmp6jSwUBHQQb5A6Hii7twKLmEjCDty1uEw9n8PMHyy zoggb57qKsv7WQ0RnHzVLe6JxQhZ/I1sZDPsqRkcIYQw+cyTpAJb4RGYFqjgpF5N1H22xa1+ UkZC1Qefib3kmhO11dZyGdgjUIngxes0MKgmXo/0cL6faJNQ7STfAx3r6wtnDimhcdVBYW6t MQ44vRjeslMfuL9h6Nl+TgRlVkkFG5rmEllvNWh3tDUZEGYLsUtoAH+lhJea1wVx4SxbpXWd WGNvusrMp+YBefdTTUr2NvyNujUjA6GQqHWFELvoiQ3yJNlH50wkMEzIhH901wua4VWt1B/a DJI65onLZBQosfar98Hv4IRY+yBnbWSRzBPWqOKRDsFb0BOXjKt5nriY9Frt2CadgN1t8/iZ 7BWFRXuSo7fF/vE9SH2NlR/hXEUAyGLELQIwFllu9EU5HHNc7W2He4OSITeuOb0oAiPvE=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.96,204,1665446400"; d="scan'208";a="19446613"
Received: from alln-core-1.cisco.com ([173.36.13.131]) by alln-iport-6.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 29 Nov 2022 21:54:56 +0000
Received: from mail.cisco.com (xfe-rcd-001.cisco.com [173.37.227.249]) by alln-core-1.cisco.com (8.15.2/8.15.2) with ESMTPS id 2ATLsuoM008109 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=OK); Tue, 29 Nov 2022 21:54:56 GMT
Received: from xfe-rtp-002.cisco.com (64.101.210.232) by xfe-rcd-001.cisco.com (173.37.227.249) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1118.9; Tue, 29 Nov 2022 15:54:55 -0600
Received: from NAM04-BN8-obe.outbound.protection.outlook.com (64.101.32.56) by xfe-rtp-002.cisco.com (64.101.210.232) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1118.9 via Frontend Transport; Tue, 29 Nov 2022 16:54:55 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=VNJMme+f44qXtdBWw9KyWy4wtywHhQ6mm1EvE/ytxd02WkhJMOlr0WGAvE6g9VCEp+GqQxXbN33ZS47LFZoXup5n0HEPfOSLq6KEmx3BPloXuns1N6Zy1lV5N2PryEQq0m0wnWIM27rdeBb5Ae8/p39Zx/QG4+i0IG5c6CuY2+JCv4Vko+cEAUFxqTkwESuGCPTRjVtyppwbBf0J1NTMYTZvywjU0okisQPLjGH7UII4jxHo75fF9OSCkrAfo7u7RqMe9Iuw1CogqbKPiY0ibNP7ZU9GaSmYmPIJh8EZ4PxvmAQuqClhp4ugIOljzhGp/d1fUwO80+riaeLT6YCN+w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=uxyYmtGONdkG9yoafsGunpByX8juviwPbB/qPjGu8EE=; b=WJunjGCtSYU8fYxSGexHQDxTeE6DCWAL0dHtS6P81k0L0zk2qfplcxpyYeNU6tBF2HkExtAjjOMCblTveUXceBW4j6W2tpsV9ntsTiFH307LsEtz6itEab5UX+5578y+6cwpF63v0dTNuluInTo6Ga00RDnfU8sbgtqpdUYPFNbL2/+Vla55p4kb8hTkQBZSn211qZegSLkG5jGw00S5laMZ4RDyZGVTAvLRA1lHXZygwfNVqMRy5qkJQJwN//pvO0JzeX7x596XtLQp3zd1NgjPgK9agAIUNaiEqTd4BRB15gBdU8nFBRz1zzc96cJVul2VDC4cs/JtPvWY33vYwQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=uxyYmtGONdkG9yoafsGunpByX8juviwPbB/qPjGu8EE=; b=SDy+EmsmRrOPzp2CZLSMy2gkaVBWXvu5IifA/jiE1+RdNE6qtB3UDoBYpTy4NcDu4i0N+xI7GaeVlatre1iy+4vGLBHmij5aUV74hi+VRvA6DMD7UTNjeM5gdjUlCRlMv85aWJSsMzPSLIb03ZH8JeCTjM67fdsP4y+38sovpeY=
Received: from PH0PR11MB4966.namprd11.prod.outlook.com (2603:10b6:510:42::21) by DM4PR11MB5971.namprd11.prod.outlook.com (2603:10b6:8:5e::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5857.23; Tue, 29 Nov 2022 21:54:48 +0000
Received: from PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::4fb9:9505:d986:8209]) by PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::4fb9:9505:d986:8209%6]) with mapi id 15.20.5857.023; Tue, 29 Nov 2022 21:54:48 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: Valery Smyslov <svan@elvis.ru>, 'The IESG' <iesg@ietf.org>
CC: "draft-ietf-ipsecme-ikev2-multiple-ke@ietf.org" <draft-ietf-ipsecme-ikev2-multiple-ke@ietf.org>, "ipsecme-chairs@ietf.org" <ipsecme-chairs@ietf.org>, "ipsec@ietf.org" <ipsec@ietf.org>, "kivinen@iki.fi" <kivinen@iki.fi>, "charliep@computer.org" <charliep@computer.org>, "gih@apnic.net" <gih@apnic.net>
Thread-Topic: Éric Vyncke's No Objection on draft-ietf-ipsecme-ikev2-multiple-ke-10: (with COMMENT)
Thread-Index: AQHZBBqcxTLa/a5Y8Eq8UMXCcvBxIK5WgvCA
Date: Tue, 29 Nov 2022 21:54:48 +0000
Message-ID: <9F638EF3-9E79-42C2-9318-1353703D2A7B@cisco.com>
References: <166971468911.7554.15756404808608648113@ietfa.amsl.com> <150a01d9041a$9c8b3590$d5a1a0b0$@elvis.ru>
In-Reply-To: <150a01d9041a$9c8b3590$d5a1a0b0$@elvis.ru>
Accept-Language: fr-BE, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.67.22111300
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cisco.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH0PR11MB4966:EE_|DM4PR11MB5971:EE_
x-ms-office365-filtering-correlation-id: 08a5ae89-90da-4cd2-ebef-08dad25455e2
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: Sp0y14Oy9QC3XoWFL/1/nq9Xph+5L1sheUWI5MqiKBi3dHaMcuZKR28e9m2ybxScfp/KZ/QgkuZXc6BAT2htEFiXed9TAWnmA695+yIDw75pO9zVBl8DOiOWChJlCA2fJuUJ5XIKgtg56LB9nm7gXvINWFMU04d4+9m2lMzGbkerD8nQsj36ZLh7meac68+7o6/wm2aYN/naaE76aOqEXNJb5LCijWGejoa1hT2YA3wjGxQ1CdCdCP0x0vImVw5prV4rhOatVln+8pXNUFwyVJsumB/soQOtqS/vsFwiq5xC82K2SC4GSkXW4Wihp81mzKjBLcWtnkuuwEPB6Fa1TsJW2HW8NRfNQWc0jiMqbu4KS3DgLyEanDmsdEt9sIBMXtDpyrGX8Pxm74HBdnTiw7Iaz7g+0JEjcGS4qYq1GbgZ9sqwkGHZjZFgCnw+1x153lqnevNiAqQ7hwQ5yHprGY3c57DhN2D6d6U6+lf6eeMvAqAr9nmgcF8gPYj7P40JAaCrESRNZ+u+oWgAMxQfYJi2vlefP1+6YlF/vYu8agQd68COivQjSoZ3pbr7fkWsuUNO3vIFla/g3TKRZlSWnOjR+iXmO5SXes8ngnDj9laqRnxL76zENwkTg7THY6UcXXD3YVYY6v0fB2vL74MMeS8Z1L7CCQSWkFwcFKOgYw9s5wvP6QUahQs/qqhcedAgnIySM0lkoqWv9WV2pdP6xdBRU+AH8Mxx0i84fMsbrHGa7J8xgXI8bLQVvT4I7YY+v/+DHtlbITPPNpPubQENrkiRHRkNZ+SkQfnO7GFO1gk=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH0PR11MB4966.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(366004)(39860400002)(376002)(346002)(136003)(396003)(451199015)(33656002)(224303003)(71200400001)(86362001)(6506007)(6512007)(54906003)(36756003)(53546011)(316002)(110136005)(122000001)(38100700002)(66556008)(66574015)(4001150100001)(2906002)(83380400001)(64756008)(66446008)(76116006)(66946007)(66476007)(4326008)(91956017)(8936002)(5660300002)(2616005)(41300700001)(186003)(38070700005)(966005)(6486002)(478600001)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: /uqgQuLz+efuKwLMmWaRP5jRF7PAzoZpeGM18Adk/XXtcfDoEjcbvvVhBasd5ZATLFQymK6Y4RKMqDEnFCYG9I49mEsIgmd3+xQmwEksLyNepxdWfyetc1GpP8R7bQ2548TadcbE4KPsnEiwy1RpKq7X8pqo19WA2MHJUfL/aEyPbkgSiLEbEHqjpBjOZpq4X2V4xxVKJUbq+hnE3qubuvNmKD0Z8aYxfa5jGPdqwLGgKzJB5LSPEQrtB6GmUQYUkGza+v481/Atw7HJ0nzL8LOrvesX3q+goxjomjiaWnPC12020LZcPh0eJyzc7ETsGaZRc2432L0RQTi83GyxG4xoC9up6akCffIY/I1cdgUZUDyjNeFFbuMbrGwk3o1sU8QqP24wVhU7L556KPouf1N/r1kTy2IBUK8RRxHUdf6xtAFc5EAXqGMFAwIRcK/Pjqy15MfTjgWMIXapqf17GOnHSkzjasKLIUD3MK1oZSqcKnLWPTbWHRI8YXpYt5YL92KpDsDFriAmVWAgwxKVHmI1nSy51bpOIb14z9QKuhi4cs1LGUMB0vvbB8tEsgLEDJ/aKB9uljzxZ5wrtOx+ujeGH1Kh/oOH3kuNtOX5WTAG/lqJHrDaHoO5+sSYlJSPDj1P4hAV1hJCtX+eNDcqg6co9KQ/bHtS6S4nlqqoJRMB7Ni1omujZiIBSwu53MkkQKCQZxoUVoS4fLWv2qcxvF+hmEJJKu9077o/ra+7/QZedVp2Qi2968ADvt5w9RONQKUHOxLW9N1mTYnKVSS7H2XSuEYjBpiT60xcQG5foXJ5G+tKbnEPE5tu5k0cOprXmnLivdcus7tOuwagqry5WzcNhYIfmAHOw/Td4weZvCRyw2I7LFRBXMAzyaD3yBorapT+oSWvV+DA3Um9fOHoHfQOOrKEQFpX+hOfG8I61sychxQqPHKcB48Qt7Jdq4yExc16Wt/qHJs0pzMOS6CmiCattaT+ew+f4Fe+jHfCMV8+J381cpWxPX+SBw0eHAxYWpqvbHmwTbDJq+svlKMRmbP+Q+pF967gpo7py2geAkVGeuG2IfUlCxCGa1hXGv5hQoXeanNHVXCygZ70wlrG3NT9nit0Zfnhh57XyqfJQ7E//U9GEX7VLso7mNAOsRb5wkqQWAtGAIN/5sK52/PUe7ScaKRaPIOsZdotuWpAjZZhe/u7fSOeavLQCtOlcRsT2l2R9qr1ZRiGM2Kaq6mB+z6TFc/7Yywa2zac7HWZKEHVtvZT7tSwlCbVMiVkdTi/3N5469SHFd6w3R9V+KKCGO+a8glbwPmSwkzfl/iWB2+NqzqSXttvYNLUfNkhgpi8vM+82cNZGW7q0xhaRJLNqEbR6oColV3dbBQRgSVffSRjM+CWZqshmQDanbdMFehyZ5bCu56hDudCwrX2x3S6kR/HCmv9eTovhkBdHGFx1l9X1RMuudS0kEkWBePR0/bXivARQmPqVuTN1peIhCHOQAeBOD3SVwEw/9tjOLPHiTK55f+qC5aMdmvpkWWhXnYVsJFG+ypPvXuJhjowBfxji3hEr2+G35slGOTbRIFoOLz1GT9D2f3RACZv2Ee0Z/m46TKXhfqLOZ/uPfLhWhnk5yyEKh1FqtoUqQWKVWQ2ARqEpC7PM257m48lW6mnCs66
Content-Type: text/plain; charset="utf-8"
Content-ID: <C80D77FD12874644AD582F91ED1C90E4@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR11MB4966.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 08a5ae89-90da-4cd2-ebef-08dad25455e2
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Nov 2022 21:54:48.4805 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ITTItnIfIBb4RQD6fwKqEH5WmwEpna+OwwGm4NOI+6KADouUbqfJMjPGqErFVoCSkmgS5tUwkbob6MpNCRpxoQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM4PR11MB5971
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.227.249, xfe-rcd-001.cisco.com
X-Outbound-Node: alln-core-1.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/FwHdYS_2j7M8E8WGGXki_0BQR1M>
Subject: Re: [IPsec] Éric Vyncke's No Objection on draft-ietf-ipsecme-ikev2-multiple-ke-10: (with COMMENT)
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Nov 2022 21:55:01 -0000

Hello Valery,

TL;DR:  Thanks for your reply and your comments. I agree with them ;-)

If you want a more detailed reply, then look for EV> below

Regards

-éric


On 29/11/2022, 18:47, "Valery Smyslov" <svan@elvis.ru> wrote:

    Hi Éric,

    thank you for your comments. Please see inline.

    > -----Original Message-----
    > From: Éric Vyncke via Datatracker [mailto:noreply@ietf.org]
    > Sent: Tuesday, November 29, 2022 12:38 PM
    > To: The IESG
    > Cc: draft-ietf-ipsecme-ikev2-multiple-ke@ietf.org; ipsecme-chairs@ietf.org; ipsec@ietf.org;
    > kivinen@iki.fi; kivinen@iki.fi; charliep@computer.org; gih@apnic.net
    > Subject: Éric Vyncke's No Objection on draft-ietf-ipsecme-ikev2-multiple-ke-10: (with COMMENT)
    > 
    > Éric Vyncke has entered the following ballot position for
    > draft-ietf-ipsecme-ikev2-multiple-ke-10: No Objection
    > 
    > When responding, please keep the subject line intact and reply to all
    > email addresses included in the To and CC lines. (Feel free to cut this
    > introductory paragraph, however.)
    > 
    > 
    > Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
    > for more information about how to handle DISCUSS and COMMENT positions.
    > 
    > 
    > The document, along with other ballot positions, can be found here:
    > https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-multiple-ke/
    > 
    > 
    > 
    > ----------------------------------------------------------------------
    > COMMENT:
    > ----------------------------------------------------------------------
    > 
    > 
    > # Éric Vyncke, INT AD, comments for draft-ietf-ipsecme-ikev2-multiple-ke-10
    > CC @evyncke
    > 
    > Thank you for the work put into this document. Even if my IPsec knowledge is
    > now very dated, I find it relatively easy to read.

    Thank you.

    > Please find below some non-blocking COMMENT points (but replies would be
    > appreciated even if only for my own education), and some nits.
    > 
    > Special thanks to Tero Kivinen for the shepherd's write-up including the WG
    > consensus *but* the justification of the intended status is missing.
    > 
    > Other thanks to Geoff Huston for his Last Call DNS directorate review at:
    > https://datatracker.ietf.org/doc/review-ietf-ipsecme-ikev2-multiple-ke-07-dnsdir-lc-huston-2022-10-10/
    > 
    > Please note that Charles Perkins is the Internet directorate reviewer (at my
    > request) and you may want to consider this int-dir reviews as well when Charles
    > will complete the review (no need to wait for it though):
    > https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-multiple-ke/reviewrequest/16618/
    > 
    > I hope that this review helps to improve the document,
    > 
    > Regards,
    > 
    > -éric
    > 
    > ## COMMENTS
    > 
    > Out of all Paul Wouters's points, I support the last one about AH (I am not
    > experience enough to appreciate the other ones). It is also related to bullet
    > 3) of section 2.

    I have already commented this in my response to Paul.
    So, the document focuses on PQ security, but also has
    another application in mind - the ability to combine 
    several different key exchange methods so, that the resulting
    shared secret depends on all of them. This can be useful 
    without any PQ algorithms - e.g. in a situation
    when each of the peers trust only its favorite
    key exchange algorithms, so that there is no any single
    one that is trusted by the both. In this case the draft 
    allows to use two, so that each peer will be sure
    that its favorite algorithm is used.

EV> indeed, this feature escaped me

    In this context AH still may be used
    (well, it is not deprecated yet?).

EV> no comment about AH deprecation ;-)

    > ### Missing reference RFC 8247
    > 
    > As indicated by idnits tool, RFC 8247 is used as a reference but is not defined
    > ;-)

    Ah, we managed to confuse idnits (which in fact is not too difficult) :-)

    This document does not reference RFC 8247, but it contains 
    the text to be placed at the IANA registry page as a Note,
    and this text contains a "[RFC8247]", but this reference 
    is in the context of IANA page :-)

EV> I should have better eyes... sorry

    > ### Section 2
    > 
    > The bullet 2) is a nice explanation about *why* there must be multiple key
    > exchanges with different methods. Until reading that part, I was really
    > wondering why this I-D was about the link with PQC and multiple key exchanges.
    > Should this be mentioned in the abstract already ?

    I don't mind, but as far as I know, IESG wants abstract to be short :-)
    If you (and other ADs) think it's a good idea, then we'll add this text.

EV> I know about short abstract, but they should also give an idea of the content & purpose

    > Should "FIPS" be prefixed by "USA" as in "USA FIPS" ?

    I don't know, rely on my co-authors (actually it seems that 
    this is a well-known organization outside USA, but formally you are right).

EV> I live a in Federal state as well (Belgium), so while I understand that FIPS stands for the USA one, let's be inclusive. Up to you and the authors.

    > ## NITS
    > 
    > ### Section 1.2
    > 
    > `payloads longer than 64k` suggest to specify the units of measure.

    Changed to 64 Kbytes.

    Thank you!

    The updated PR is available at:
    https://github.com/post-quantum/ietf-pq-ikev2/pull/22


    Regards,
    Valery.


    > ## Notes
    > 
    > This review is in the ["IETF Comments" Markdown format][ICMF], You can use the
    > [`ietf-comments` tool][ICT] to automatically convert this review into
    > individual GitHub issues.
    > 
    > [ICMF]: https://github.com/mnot/ietf-comments/blob/main/format.md
    > [ICT]: https://github.com/mnot/ietf-comments
    >