Re: Deletion of SA
Michael Richardson <mcr@sandelman.ottawa.on.ca> Mon, 23 March 1998 14:49 UTC
Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id JAA22422 for ipsec-outgoing; Mon, 23 Mar 1998 09:49:58 -0500 (EST)
Message-Id: <199803231507.KAA00292@morden.sandelman.ottawa.on.ca>
To: ipsec@tis.com
Subject: Re: Deletion of SA
In-reply-to: Your message of "Mon, 23 Mar 1998 18:56:42 +0500." <3.0.1.32.19980323185642.006aa2e8@192.9.200.10>
Date: Mon, 23 Mar 1998 10:07:33 -0500
From: Michael Richardson <mcr@sandelman.ottawa.on.ca>
Sender: owner-ipsec@ex.tis.com
Precedence: bulk
>>>>> "K" == K SrinivasRao <srinu@trinc.com> writes:
K> since it has not received all the messages. Now, if this SA in
K> H2 is not shared between security policy entries, it will
K> remain forever (until the system reboots) as H1 would have
H2 may have a (configurable) maximum lifetime on all SA's as well. I
think this would be a prudent implementation detail.
K> negotiated a new SA and will use that for future
K> communications. Should H1 send a delete payload to delete H2's
Yes. That should occur as part of the new SA being setup.
A question though: is a "delete" too strong here? Perhaps a "please
delete this SA in X seconds" would be more appropriate? As a notify
perhaps? That would allow SA's to be negotiated in advance of being
used, and it also allows the network to drain.
Someone tell me that this is already addressed, but I just missed
that part :-)
K> negotiation of a new SA to send this packet on. How does H2
K> delete the SA it has? By getting a delete payload from H1? Or,
K> it expires in the normal way?
I think a sender should always try and send a delete payload when it
removes an outgoing SA.
] Network Security Consulting and Contract Programming | SSH IPsec [
] Michael Richardson, Sandelman Software Works, Ottawa, ON |international[
] mcr@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |strong crypto[
] panic("Just another NetBSD/notebook using, kernel hacking, security guy"); [
- Deletion of SA K SrinivasRao
- Re: Deletion of SA Michael Richardson
- Re: Deletion of SA Daniel Harkins
- Re: Deletion of SA Bill Sommerfeld
- Re: Deletion of SA Scott G. Kelly
- Re: Deletion of SA Scott G. Kelly
- Re: Deletion of SA K SrinivasRao
- Re: Deletion of SA K SrinivasRao
- Re: Deletion of SA Scott G. Kelly
- Re: Deletion of SA S. B. Kulkarni
- Re: Deletion of SA Scott G. Kelly
- (administrivia) About my archives Michael C. Richardson
- Re: Deletion of SA S. B. Kulkarni