Re: Specification of tunnel/transport attribute in IKEv2

"Prof. Ahmed Bin Abbas Ahmed Ali Adas" <alaadas@kaau.edu.sa> Wed, 15 May 2002 08:01 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g4F81XL25267; Wed, 15 May 2002 01:01:33 -0700 (PDT)
Received: by lists.tislabs.com (8.9.1/8.9.1) id DAA03346 Wed, 15 May 2002 03:10:33 -0400 (EDT)
Message-ID: <001501c1fbe1$02a0f1c0$4d17fea9@amanda2>
From: "Prof. Ahmed Bin Abbas Ahmed Ali Adas" <alaadas@kaau.edu.sa>
To: Henry Spencer <henry@spsystems.net>, Markku Savela <msa@burp.tkv.asdf.org>
Cc: andrew.krywaniuk@alcatel.com, ipsec@lists.tislabs.com
References: <Pine.BSI.3.91.1020514203259.14998A-100000@spsystems.net>
Subject: Re: Specification of tunnel/transport attribute in IKEv2
Date: Wed, 15 May 2002 10:20:32 +0300
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
Disposition-Notification-To: "Prof. Ahmed Bin Abbas Ahmed Ali Adas" <alaadas@kaau.edu.sa>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

In protocol architecture, the policy making should be totally isolated from
the Key Agreement Protocols or Key Transport Protocols.

Ahmed


----- Original Message -----
From: "Henry Spencer" <henry@spsystems.net>
To: "Markku Savela" <msa@burp.tkv.asdf.org>
Cc: <andrew.krywaniuk@alcatel.com>; <ipsec@lists.tislabs.com>
Sent: Wednesday, May 15, 2002 3:34 AM
Subject: Re: Specification of tunnel/transport attribute in IKEv2


> On Sat, 11 May 2002, Markku Savela wrote:
> > If IKE negotiated only keys, these ordering issues would never have
> > surfaced.
>
> On the contrary:  they would have surfaced, in whatever other protocol
> was devised to handle the policy checking.
>
> Simply removing these issues from IKE does not make them go away.
>
>                                                           Henry Spencer
>                                                        henry@spsystems.net
>
>