The following errata report has been held for document update 
for RFC8229, "TCP Encapsulation of IKE and IPsec Packets". 

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid5320

--------------------------------------
Status: Held for Document Update
Type: Technical

Reported by: Valery Smyslov <val...@smyslov.net>
Date Reported: 2018-04-09
Held by: Paul Wouters (IESG)

Section: GLOBAL

Original Text
-------------


Corrected Text
--------------
TCP provides reliable transport, so there is no need for applications 
to deal with retransmissions. Moreover, sending retransmissions by IKE 
in case of TCP on congested networks could further increase congestion 
and degrade performance. For this reason IKE initiators SHOULD NOT 
retransmit requests if they are sent over TCP. However, both IKE 
initiators and responders MUST correctly handle retransmitted messages 
received over TCP, but responders SHOULD NOT resend response messages 
in this case. If IKE initiators still choose to retransmit requests 
over TCP, then the retransmission policy SHOULD be less aggressive than 
it would have been in case of UDP.


Notes
-----
While Section 12.2 discusses some implications that TCP transport could have on 
ESP protocol, the IKE retransmission behavior, described in Section 2.1 of 
RFC7296, is not redefined by this RFC. This is an oversight and some 
recommendations for implementers should have been given. The suggested text 
should be placed in a new section, presumably between sections 8 and 9.

Paul Wouters:

The reported of this errata is writing a bis draft for this document where this 
is indeed already clarified.
See 
https://datatracker.ietf.org/doc/html/draft-ietf-ipsecme-rfc8229bis-05#section-7.2

Resolving as Held for Document Update

--------------------------------------
RFC8229 (draft-ietf-ipsecme-tcp-encaps-10)
--------------------------------------
Title               : TCP Encapsulation of IKE and IPsec Packets
Publication Date    : August 2017
Author(s)           : T. Pauly, S. Touati, R. Mantha
Category            : PROPOSED STANDARD
Source              : IP Security Maintenance and Extensions
Area                : Security
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to