Hi,

Eric Levy-Abegnoli <[email protected]> writes:

> Sheng,
> Currently, I see onle one possibility, which is A. It is
> un-ambiguously specified in rfc3971.

I respectfully disagree (not on the definitive solution). My previous
post in March 2008 and the one from Sheng just prove this is not
"un-ambiguously" specified. 

> And it has been implemented by multiple vendors.

I checked the code and NTT Docomo SEND daemon does 'A' (i should have
checked before my first reply to Sheng):

It computes the checksum on current ICMPv6 message before the Signature
computation, uses that during the signature step and then recomputes the
checksum after the signature option has been added to the message.

> Moving to B would not be backward compatible and would create
> inter-operability issues.

Clarifying the spec would help in all cases.

Cheers,

a+
_______________________________________________
CGA-EXT mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/cga-ext

Reply via email to