Re: question on "code preserving" section in Paul's draft

Michael Thomas <mat@cisco.com> Wed, 15 May 2002 23:18 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g4FNIZL13910; Wed, 15 May 2002 16:18:35 -0700 (PDT)
Received: by lists.tislabs.com (8.9.1/8.9.1) id SAA05430 Wed, 15 May 2002 18:37:11 -0400 (EDT)
From: Michael Thomas <mat@cisco.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Message-ID: <15586.58895.262379.898025@thomasm-u1.cisco.com>
Date: Wed, 15 May 2002 15:49:51 -0700
To: Dan Harkins <dharkins@tibernian.com>
Cc: Michael Thomas <mat@cisco.com>, ipsec@lists.tislabs.com
Subject: Re: question on "code preserving" section in Paul's draft
In-Reply-To: <200205152056.g4FKuUk09579@trpz.com>
References: <15586.43515.644098.353766@thomasm-u1.cisco.com> <200205152056.g4FKuUk09579@trpz.com>
X-Mailer: VM 6.72 under 21.1 (patch 6) "Big Bend" XEmacs Lucid
X-Face: &, heK/V66p?[2!i|tVn, 9lN0TUvEv7:9FzXREj/AuzN4m<D]vnFJ>u!4x[/Z4t{V}~L]+Sk @RFNnJEg~WZ/(8<`5a), -7ukALWa^&?&D2R0CSG3kO5~#6JxLF\d, g">$%B!0w{W)qIhmwhye104zd bUcI'1!
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

Dan Harkins writes:
 >   It is not our intention to say "MUST implement" IKEv1. If you have
 > already implemented IKEv1 then there will be things, like the payload
 > parsing code, that can be reused when writing IKEv2. If you have not
 > implemented IKEv1 then "code preservingness" is a non-issue. We're
 > not forcing people to write IKEv1 so they can reuse code when implemen-
 > ting IKEv2. Definitely not.
 > 
 >   I didn't get that impression from the draft but if you did then
 > most likely more people did too. What's the particular text that gave
 > you that impression so it can be re-whacked?

Dan, 

This is hearsay on my part from Paul's SOI
feature's draft in section 6.2. There's some
speculation about bid down attacks, and in
particular the last paragraph it seems to imply
that it wouldn't be a big deal because IKEv1
is secure... and by extension available.

That's what I was trying to get clarification on.

	    Mike