IKE Minor version

Tero Kivinen <kivinen@ssh.fi> Tue, 29 June 1999 18:26 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by mail.proper.com (8.8.8/8.8.5) with ESMTP id LAA28528; Tue, 29 Jun 1999 11:26:59 -0700 (PDT)
Received: by lists.tislabs.com (8.9.1/8.9.1) id LAA11520 Tue, 29 Jun 1999 11:15:49 -0400 (EDT)
Date: Tue, 29 Jun 1999 18:15:23 +0300
Message-Id: <199906291515.SAA24604@torni.ssh.fi>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
From: Tero Kivinen <kivinen@ssh.fi>
To: Will Price <wprice@cyphers.net>
Cc: ipsec@lists.tislabs.com
Subject: IKE Minor version
In-Reply-To: <377800A6.9E7E0195@cyphers.net>
References: <377800A6.9E7E0195@cyphers.net>
X-Mailer: VM 6.34 under Emacs 19.34.2
Organization: SSH Communications Security Oy
X-Edit-Time: 4 min
X-Total-Time: 2 min
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

Will Price writes:
> I didn't see anything in the new IKE draft about bumping the minor
> version number.  Since some methods have changed such as how one goes
> about deleting SAs (the new Acknowledged Exchange), it seems that it
> would be appropriate to change the IKE version described in the new
> draft to 1.1 rather than 1.0.  This should allow existing IKE clients
> to continue to function with new clients while allowing new clients
> to use the new features.

There is no reason to bump up the version number of the ISAKMP because
of those changes. The new acknowledged notification exchange is using
new exchange type, so old implementations will just send back invalid
exchange type notification, and new version can detect the lack of
support for that from there.

See my "IKE Extensions Methods" (draft-ietf-ipsec-ike-ext-meth-01.txt)
draft for more information when and how we should bump up the version
number. 
-- 
kivinen@iki.fi                               Work : +358-9-4354 3218
SSH Communications Security                  http://www.ssh.fi/
SSH IPSEC Toolkit                            http://www.ssh.fi/ipsec/