Re: [IPsec] diet-esp - How do you know?

"Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com> Tue, 24 May 2022 15:31 UTC

Return-Path: <sfluhrer@cisco.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7CCFBC18D824 for <ipsec@ietfa.amsl.com>; Tue, 24 May 2022 08:31:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.595
X-Spam-Level:
X-Spam-Status: No, score=-9.595 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=il5cAARD; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=LCb7obSM
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eMrLi6a7l1pm for <ipsec@ietfa.amsl.com>; Tue, 24 May 2022 08:30:57 -0700 (PDT)
Received: from rcdn-iport-4.cisco.com (rcdn-iport-4.cisco.com [173.37.86.75]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 63DD5C18D820 for <ipsec@ietf.org>; Tue, 24 May 2022 08:30:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=8638; q=dns/txt; s=iport; t=1653406257; x=1654615857; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=YbvrAqDHzIU4nKtI/ZWUbfn6yqJ9aP/fytY1X4tOKxM=; b=il5cAARDJLxISopAbGZbdPiiA9xAXkL1mhlqi1t0MdlE5EnZz5IxYfHZ 6avGH3zL4B9mKMc3rHRuecHZagnaLUY3KFFTYxBJ+9eNQ/e0zQUbcTXhd Bit2CMRPKdafR85AdQl1M/qImjNVeiCo41dkhOsq0BcqAYPYK88fKqhpF k=;
IronPort-PHdr: A9a23:5ixj4hUE214M73N7+linJR8xwjHV8K36AWYlg6HPw5pCcaWmqpLlOkGXpfBgl0TAUoiT7fVYw/HXvKbtVS1lg96BvXkOfYYKW0oDjsMbzAAlCdSOXEv8KvOiZicmHcNEAVli+XzzMUVcFMvkIVPIpXjn5j8JERK5Pg1wdYzI
IronPort-Data: A9a23:L3b6Na6LlOukneG3toDxVwxRtObFchMFZxGqfqrLsTDasY5as4F+vmpKWDjSb/eDM2Hyf9Enb9uzphlT6p7Ry4AyTVFppXpgZn8b8sCt6fZ1gavT04J+FiBIJa5ex512huLocYZlFxcwmj/3auK79SQli/nRLlbBILes1h5ZFFcMpBgJ0XqPq8Zh6mJZqYDR7zGl4LsekOWHULOR4AOYB0pPg061RLyDi9yp0N8QlgRWifmmJzYynVFNZH4UDfnZw3cV3uBp8uCGq+brlNlV/0vD9BsrT9iiiLu+KxVMSb/JNg/IgX1TM0SgqkEd/WppjeBqb7xFNRk/Zzahx7idzP1Wu5itSR0kJIXHmf8WVF9TFCQW0ahuoeefcCbv6p3OkCUqdFOpmZ2CFnoePJUD9+1fAGxS+7ofMj9lRgqMgqetzbmTSvVww88kKtL2OJ9ZsXZlpRnBBOsiB4/EXrnH/8QNgG85h95DG7DfYOIVbDN1Z1LBbgFBfFANB/oDcE2A7pXkWydTpFTQrq0t7i2KlEp60aPmN5zefdnieCmcpW7AzkquwogzKk1y2ASj9Ae4
IronPort-HdrOrdr: A9a23:XWfon6g2JpqWA5wENpbQvCVwwHBQX2513DAbv31ZSRFFG/FwyPrBoB1L73DJYWgqNE3IwerwRJVpQRvnhPpICPoqTMiftWjdySeVxeRZjLcKrAeQYxEWmtQtt5uINpIOdeEYbmIKwvoSgjPIaOrIqePvmMvD6IeurEuFDzsaEZ2IhD0JbTpzZ3cGPTWucqBJcqZ0iPA3wgaISDAyVICWF3MFV+/Mq5ngj5T9eyMLABYh9U2nkS6owKSSKWnX4j4uFxd0hZsy+2nMlAL0oo+5teug9xPa32jPq7xLhdrazMdZDsDksLlVFtyssHfpWG1SYczBgNkHmpDr1L/sqqiJn/4UBbUx15oWRBDznfKi4Xin7N9k0Q6d9bbRuwqTnSW+fkNiNyKE7rgpKScwLCEbzYlBOetwrhKknosSAhXakCvn4d/UExlsi0qvuHIn1fUelnpFTOIlGfRsRKEkjQpo+a07bWrHAUEcYZ1TJdCZ4OwTfUKRbnjfsGUqyNuwXm4rFhPDRkQZoMSa3zVfgXg8liIjtYEit2ZF8Ih4R4hP5uzCPKgtnLZSTtUOZaY4AOsaW8O4BmHEXBqJOmOPJlbsEr0BJhv22tTKyaRw4PvvdI0DzZM0lpiEWFREtXQqc0arEsGK1I0jyGG6fIx8Z0Wb9ihz3ekKhlSnfsuZDcSqciFar/ed
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AzBgAHbIJi/5JdJa1aHgEBCxIMggQLgSExUgd1Alg5Q4ROg0wDhTGFCYMFliWFE4EsgSUDVAsBAQENAQE5CQQBAYUCAhaFKAIlNAkOAQIEAQEBEgEBBQEBAQIBBwSBCROFaA2GQgEBAQEDEhEKEwEBNwEPAgEIEQQBASgDAgICMBQJCAIEAQ0FCBqCXIIMVwMxAQ6fZwGBPgKKH3qBMYEBgggBAQYEBIE7AhBBgn8YgjgDBoE8gxSEJwEBhyMnHIFJRIFYgmc+gmIBAQIBgV8VFgmDIDeCLoFmk3sHOgNUgQUSgSFxAQgGBgcKBTIGAgwYFAQCExJTHgITDAocDlQZDA8DEgMRAQcCCxIIFSwIAwIDCAMCAyMLAgMYCQcKAx0IChwSEBQCBBMfCwgDGh8tCQIEDgNDCAsKAxEEAxMYCxYIEAQGAwkvDSgLAwUPDwEGAwYCBQUBAyADFAMFJwcDIQcLJg0NBBwHHQMDBSYDAgIbBwICAwIGFwYCAnEKKA0IBAgEHB4lEwUCBzEFBC8CHgQFBhEJAhYCBgQFAgQEFgICEggCCCcbBxY2GQEFXQYLCSMcHAEPCwYFBhYDJlIFBB8BklmDHQiCJ0AyHwKBXguWeIl5n1OBMAqDTIsalQwVqFeHHo9III0HlFiEfwIEAgQFAg4BAQaBYTyBWXAVgyNRGQ+OIINyhRSFSnU7AgYBCgEBAwmRGgEB
X-IronPort-AV: E=Sophos;i="5.91,230,1647302400"; d="scan'208,217";a="1009683957"
Received: from rcdn-core-10.cisco.com ([173.37.93.146]) by rcdn-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 24 May 2022 15:30:56 +0000
Received: from mail.cisco.com (xfe-rcd-005.cisco.com [173.37.227.253]) by rcdn-core-10.cisco.com (8.15.2/8.15.2) with ESMTPS id 24OFUuHE029877 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=OK); Tue, 24 May 2022 15:30:56 GMT
Received: from xfe-rcd-002.cisco.com (173.37.227.250) by xfe-rcd-005.cisco.com (173.37.227.253) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.14; Tue, 24 May 2022 10:30:55 -0500
Received: from NAM10-BN7-obe.outbound.protection.outlook.com (72.163.14.9) by xfe-rcd-002.cisco.com (173.37.227.250) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.14 via Frontend Transport; Tue, 24 May 2022 10:30:55 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cPTjJguVajfAAjPMtUZKVWndajALPVXDskxdma5r+RNtA7dKG4cAf0dXkVEA/P51SCVssvzWOHR9B72NN/Zoxc+ncA8DtIYdcYMpf4S1Zs/DqUzzzYS4+fRz8NGo7PNek7DJj/c+sob83oCZ9rg6K+fftTvW2HZ9xN23p8vQDY//hkEn6m+EEK65CRBxSThHv/U9YOISKMPL4vaVFr+dLedGnrPGtH75ly9B8BpBCWhFgdtRQqpz2CJBrafWKz9wORfsdPc5ME4treg+1RP8scsKMvN2f5KUY0Pw64WjmvCGGre0Z1R0lRmai+DVBXDvA++kTfjRaeKPoWFffQykhg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=YbvrAqDHzIU4nKtI/ZWUbfn6yqJ9aP/fytY1X4tOKxM=; b=a2JoRDwHmOF1VIcLTORBuqvG5x22Fk8rLWDzUooU5+MZx/zK1z7oNFJIQjbLZOU2c0qlTAe0ChVwLrpeXF6GcKwKnyE51lyY8dind5KWLUkEfODRPjeIdijgBAHzYp+yypy3Zc840jkOokwPOyDuGaxHCzhR2RP5T5ENVB8hY2zNWHDnh5kvjUV3bypV2q2C/ESEfvUSN3iCSc4hPN2nfVZwzxrFBg+9Y1pNWNgXmxendH+KSRdB46NOdflf343hkbcBBeD7rsTvxZfSppM+IGANvg/sAeqCfnll7jTcBP4WIKGgl0XvdmLI78ZGdR9sjer5GJ5PpPjI2vXYEksQvQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=YbvrAqDHzIU4nKtI/ZWUbfn6yqJ9aP/fytY1X4tOKxM=; b=LCb7obSMLdne5Aapt202+aLsdrjio+mG7GoYvJCsLSLNZ1wOpPUMNWWUsTKPKtlQCXHEbifR5RmLDD9UWraPBYKzVAy1rBIQpvHk4n2u7wagxDb8MPW7lcnQaozGrK9XvfWWr/1e00c66xflJ5Im7JASeNJyCn8HVAbVwd6VhNY=
Received: from CH0PR11MB5444.namprd11.prod.outlook.com (2603:10b6:610:d3::13) by BN8PR11MB3667.namprd11.prod.outlook.com (2603:10b6:408:88::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5273.15; Tue, 24 May 2022 15:30:54 +0000
Received: from CH0PR11MB5444.namprd11.prod.outlook.com ([fe80::3998:5d1e:d807:91a3]) by CH0PR11MB5444.namprd11.prod.outlook.com ([fe80::3998:5d1e:d807:91a3%9]) with mapi id 15.20.5293.013; Tue, 24 May 2022 15:30:54 +0000
From: "Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com>
To: Paul Wouters <paul.wouters=40aiven.io@dmarc.ietf.org>, Robert Moskowitz <rgm-sec@htt-consult.com>
CC: IPsecME WG <ipsec@ietf.org>
Thread-Topic: [IPsec] diet-esp - How do you know?
Thread-Index: AQHYbkNfaOb3j8nuIUiGuLMrFfhyx60uJScAgAADCNA=
Date: Tue, 24 May 2022 15:30:54 +0000
Message-ID: <CH0PR11MB5444CB9D09A4C0E638D948F5C1D79@CH0PR11MB5444.namprd11.prod.outlook.com>
References: <245277bb-6d70-dbcd-b99e-badc435b9c4d@htt-consult.com> <CAGL5yWa=hjCZD912YJPWM-x_=ChTo=yULk1P5FRfkfB9Db9+Gg@mail.gmail.com>
In-Reply-To: <CAGL5yWa=hjCZD912YJPWM-x_=ChTo=yULk1P5FRfkfB9Db9+Gg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cisco.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 0eb6485d-d7e0-4a5e-a824-08da3d9a6441
x-ms-traffictypediagnostic: BN8PR11MB3667:EE_
x-microsoft-antispam-prvs: <BN8PR11MB3667B0C594A7717444E69170C1D79@BN8PR11MB3667.namprd11.prod.outlook.com>
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: SJL8Im9HWIa90QBnfyon/OiRQ78a8Nqijfjg8P5jUl78hPT/pqg/IeUYUb+I/aFe2rsNXAXrWUD1uUrkY9q5Ax2n7GlKAkgaBR6RHTVOJLjCnItxODCVd7M4YQ+IZq6flG0mNhaGO9jQSs8ep7/hNGgwtdlsOs295FuQYndLHYPI98qM9ndaPegwL3f9y/rjex0/LKEG0f0D+HaPHXBnHhuwMBzFa7zaxUWps3iQABRoODZ6nrdc9aKeooz8Aco3HbzPSszrDZQ66Py9BogqlLS+jh1h6kdG9w/TOSA+o0IYm4/fEx9Tvs93/+b4pXKZh49/Wv4P1k9faPWXROXscUaqLxqB9ck0Bjnp1W7HIomG67QlycGI9E79/MTsKQxfmerNA+aR8ps4QG/ARXL2Dh0/bCRKdEe2sTjZ3NCUYSC3EccVkTUgxfS9f5utT7bZjFawDW4fDdJ7W5hFOJX6XxGPlA4jVDpSytrjm+HXwbJOcCUJ1su8MoMTR2ee2PaDSX8NK467Z3+1gs3zEpg+6ltFga8OwOWfEi/1cddZL67bdYDmmpWoUhj6A3DmSTa0m3Xd9Vpb1MXi1Sn+32r23sR1vKvTOu3L5ZwCDiPU5YQB24Iq0SuvAGixLOooNrLsJAiMgEn/DpZo/vG+JxNU9HxovXuHNlNy8LzFWMIzgAF5aq4d1A49zS4rC9zjDEHVYhT1tEGqQEJfzZwzIuZMGqKp18pYMSDg5wpChQMVN295LHRfe4crF6rTJBORElnHJF22q2GrIYKeUnUI5CMpJDfiHVUDElmI+hajvWL8mh8=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CH0PR11MB5444.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230001)(366004)(186003)(76116006)(166002)(38070700005)(55016003)(122000001)(38100700002)(7696005)(6506007)(66946007)(508600001)(64756008)(966005)(66556008)(110136005)(316002)(66476007)(66446008)(2906002)(71200400001)(4326008)(26005)(8676002)(53546011)(5660300002)(9686003)(52536014)(33656002)(8936002)(86362001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: /qbB0BDbTRFoYxNW9TiO6Sp4Wx4/dymwPa5JMyJ18S7FYgU85rNr1JalNtoX9p4qSDsL3uNnzPbF9vmGKFmQU+6K3WHULvDJyfVlMRjSqR1mjQxbaotI4bV3EPS/nsDacJ86b5Tg62BGBzsc13WL+hQujcyW4AjB+zI3kvh5MTc6htnhf9c4KKToTfS7+HklAHc6Oeqy8oQatc8ZvcilPeY/h3lObSmNQRHKy8/lk2EZ/Ed0XGXGJlYR8bwTZQTbjRB3aUwWwhZYjNMNaFMe4TlSIIxkRxXjB099NrCQ84jAp02WJYTue5zyNtfczsXkwwSUNxnGjF8YwgGAl61Yau4Z57OIoyYuknj8JS3h434pcZhxfdtKuh08+C8H/k+h36Jy7THYZ2o9ENlMW7z/NO2F2WynTeEE4+g5PLtD/qlvQ8pygSFhSH/rsQEG8b6G1sL0YAgJGs4yIx/pFLSE9ilFX8dobhYY6yO3mdUQyswVFy+5K7e1m90YqbXFXuq+eaSyjbxV+xXYbd+9QaR/JfaRY65X3jnxlpV9fY0eo9epQB7bX1Q05XzTKWZawbx80A/0XpStxf5Lc5mURrm1/6cTGNOoNv7PNZOaaiTNLUGw3lkZdEbh3kJ+fm2Q5rhVfoGvjXDz+4r1o5rcIwyYuh9LZCDmlHIMyWYW7LvxPcfbtBmtn6TMz7l4E7c6xYvGe5E0bYXs1E/1PR9bSSUX43CLAlywOE3gmnbLDlaWqR52iXIHR3kMSeDqIgWTl/Wi+DsdicuyAur/1xS8Mo51TWE/HPLEgFnFZmK+hOiB07dLlrptYth+0W98a3gKd9d9H9sVyDPuloX1HNQvmaWf8lffcUcSV18MGbW7fOBK6XOGq88BNHhWi1X7SZtknhzFyo5z1+YNDtHrcMhh/aQgO4vXN93N4exNc/tcKjixppXVkd0SVZjbc91KHurmChEhq4Xo7e/OVplb72cG19mru3SFX+GVfA6Hfn6JCcBzEvRXj/8jS78AoEhh+ljsarRpz2Ll4QD1mZqO6IsetkaJ5dlFujaLG3u+0YnOYNi5DslDK5bEFD1l9xI4JPlfI+i1VqSoUTfFHy7mO8PG2pDF9cy0iDx5Vt7kaKTfvt3QYcwDbiKxBmR1f69oALTnq1jRKX3vuj/J/NRy8kkEhJNE+THaLHHsKymJud9iREECTfIIwsZwpyUbV1NCp44sAY5Sj631smCLMs4+QjXKwkCz5MMwscwuu8Y6pMqFnu3kjbcFH1XbrYhgxaFLmqzMR0+VwGP7H04BbgtjnNNh+CoQEndoSOCysMsAdEM5BKa1wo3Um/Aa3ffHjB6by00DHme1rAT4IXf1RMFt9ILU39n+6BX+yHqmV7a+69T0v0HW3eKmlTPhtR+yt0jfGjbXDTMaufm5Ski8cEmMMQtlFwS07ZIHJLZQ3zNdAzcPnlsmYay328iph+g4Jxfy4l6JWgQbImNI03M8IfckJgQi8EaN6Xy8x4CpLQRDRRBjFZroZ28q4DPkZS8qP4VOTIJeLMddrjjZwfO/h2KXQkqMzLsPxIoQiAquYNlOpIc3Jc3fYH/O0C2idJS+1nAqSfwS3W+F1F+HjoO/lAwZ6cRHMwo0Ijp1W2uUlM3eoFlZbNxd2kWmLRE57w3Y7pNaus0gS+npmeIdX6s+Mclc8fG3UnJyva45xfZjjHsuZAUkc1WRx5zTqtIJIchapD+8Tf0qB9jbEktec4DaQTgFmyIVCqh8GA==
Content-Type: multipart/alternative; boundary="_000_CH0PR11MB5444CB9D09A4C0E638D948F5C1D79CH0PR11MB5444namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CH0PR11MB5444.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 0eb6485d-d7e0-4a5e-a824-08da3d9a6441
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 May 2022 15:30:54.2472 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: DD1bQ61hWlCg3asg9O533gCX8BXcCFzC0EpqCX422wXn//S2t7/V1OJMwP+37l5fvP7FETiW6nj3+xDjJM5+YQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN8PR11MB3667
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.227.253, xfe-rcd-005.cisco.com
X-Outbound-Node: rcdn-core-10.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/uN6YwIvMnLCH7xrIZqC3pP_qaqQ>
Subject: Re: [IPsec] diet-esp - How do you know?
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 24 May 2022 15:31:01 -0000

I believe that the question is “when someone receives an IPsec packet, how do they determine the SA, assuming that they have negotiated both standard SAs (with 32 bit SPIs), and diet-esp (with shorter SPIs).”

My initial assumption was that, as the receiver picks its incoming SPIs, that they pick them to allow unambiguous lookup.  For example, if a diet-esp inbound SA has an 8 bit SPI of 07, that means that the implementation ensures that it does not have any standard inbound SAs with SPIs of the form 07xxxxxxxx.

It might not be totally unreasonable if the diet draft spelled out a method for achieving this…

From: IPsec <ipsec-bounces@ietf.org> On Behalf Of Paul Wouters
Sent: Tuesday, May 24, 2022 11:14 AM
To: Robert Moskowitz <rgm-sec@htt-consult.com>
Cc: IPsecME WG <ipsec@ietf.org>
Subject: Re: [IPsec] diet-esp - How do you know?


On Sun, May 22, 2022 at 9:20 PM Robert Moskowitz <rgm-sec@htt-consult.com<mailto:rgm-sec@htt-consult.com>> wrote:
I think there is something else I am missing here.

How does the receiving system 'know' that the packet is a diet-esp packet?

https://datatracker.ietf.org/doc/html/draft-mglt-ipsecme-ikev2-diet-esp-extension-02

It's negotiated with IKEv2.

I guess the IKE stack has to signal this to the ESP implementation on what to expect when
the policy is installed ?

Paul