[IPsec] Open IKEv2 errata

Tero Kivinen <kivinen@iki.fi> Tue, 18 May 2010 10:37 UTC

Return-Path: <kivinen@iki.fi>
X-Original-To: ipsec@core3.amsl.com
Delivered-To: ipsec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4A5703A6A36 for <ipsec@core3.amsl.com>; Tue, 18 May 2010 03:37:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.21
X-Spam-Level:
X-Spam-Status: No, score=-1.21 tagged_above=-999 required=5 tests=[AWL=-0.100, BAYES_05=-1.11]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mXIaVNjlkaYP for <ipsec@core3.amsl.com>; Tue, 18 May 2010 03:37:25 -0700 (PDT)
Received: from mail.kivinen.iki.fi (fireball.acr.fi [83.145.195.1]) by core3.amsl.com (Postfix) with ESMTP id 8EB6A3A6936 for <ipsec@ietf.org>; Tue, 18 May 2010 03:37:23 -0700 (PDT)
Received: from fireball.kivinen.iki.fi (localhost [127.0.0.1]) by mail.kivinen.iki.fi (8.14.3/8.14.3) with ESMTP id o4IAb1Va000156 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 18 May 2010 13:37:01 +0300 (EEST)
Received: (from kivinen@localhost) by fireball.kivinen.iki.fi (8.14.3/8.12.11) id o4IAb0cK001669; Tue, 18 May 2010 13:37:00 +0300 (EEST)
X-Authentication-Warning: fireball.kivinen.iki.fi: kivinen set sender to kivinen@iki.fi using -f
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Message-ID: <19442.28108.255794.859480@fireball.kivinen.iki.fi>
Date: Tue, 18 May 2010 13:37:00 +0300
From: Tero Kivinen <kivinen@iki.fi>
To: Paul Hoffman <paul.hoffman@vpnc.org>
In-Reply-To: <p06240835c81767b737a8@[10.20.30.158]>
References: <20100517204502.4A74B3A6A0A@core3.amsl.com> <4BF1AFF5.9080301@ieca.com> <p06240835c81767b737a8@[10.20.30.158]>
X-Mailer: VM 7.19 under Emacs 21.4.1
X-Edit-Time: 3 min
X-Total-Time: 2 min
Cc: ipsec@ietf.org, Sean Turner <turners@ieca.com>
Subject: [IPsec] Open IKEv2 errata
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipsec>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 May 2010 10:37:26 -0000

Paul Hoffman writes:
> In specific, it would be good if the pickier folks on this list to
> look at 2195 and see if this is really just a clarification or is a
> change that limits something we don't want to limit. Comments on any
> of the others is welcome too. 

I think the change in 2195 is ok, but unneeded, as Configuration
Attribute substructure has only on value (the field inside the
configuration attribute is called value, not values, thus
configuration attribute cannot have more than one value). So only way
to send multiple attribute values is to send multiple configuration
attribute structures inside one configuration payload.

But if someone though this is not clear enough, the change is
harmless, and can be done. 
-- 
kivinen@iki.fi