The following errata report has been rejected for RFC7296,
"Internet Key Exchange Protocol Version 2 (IKEv2)".

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid8407

--------------------------------------
Status: Rejected
Type: Technical

Reported by: Yan Jia <[email protected]>
Date Reported: 2025-05-07
Rejected by: Deb Cooley (IESG)

Section: 2.15.

Original Text
-------------
InitiatorSignedOctets = RealMessage1 | NonceRData | MACedIDForI

NonceRPayload = PayloadHeader | NonceRData

Corrected Text
--------------
InitiatorSignedOctets = RealMessage1 | Nr| MACedIDForI

NonceRPayload = PayloadHeader | Nr

Notes
-----
I'm not sure whether "NonceRData" and "NonceIData " refers to Nr and Ni? I 
searched "NonceRData" but I cannot find its definition. 

BTW, because we have already included "MACedIDForI" that is generated from 
Nonce in InitiatorSignedOctets, can we remove "NonceRData" from 
InitiatorSignedOctets (assuming NonceRData is Nr)?
 --VERIFIER NOTES-- 
The proposed change is wrong. Nr in the RFC7296 diagrams
represents the whole Nonce payload, including payload header,
while only its content is included in to the authentication data.

This is expressed by the line:

NonceRPayload = PayloadHeader | NonceRData

The correct change would be:

Nr = PayloadHeader | NonceRData

However, while terms NonceRPayload, InitiatorIDPayload,
RealMessage1, etc., are not formally defined in the RFC,
the explanation text above makes it clear what is meant.

--------------------------------------
RFC7296 (draft-kivinen-ipsecme-ikev2-rfc5996bis-04)
--------------------------------------
Title               : Internet Key Exchange Protocol Version 2 (IKEv2)
Publication Date    : October 2014
Author(s)           : C. Kaufman, P. Hoffman, Y. Nir, P. Eronen, T. Kivinen
Category            : INTERNET STANDARD
Source              : IP Security Maintenance and Extensions
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to