[IPsec] Questions to IKEv2bis draft: IVs of retransmitted packets

2009-09-01 Thread naoyoshi ueda
Hi All, I have a question about IVs of retransmitted packets. According to ikev2bis-04 section 2.1: > A retransmission from the initiator > MUST be bitwise identical to the original request. That is, > everything starting from the IKE Header (the IKE SA Initiator's SPI > onwards) must be

[IPsec] Questions to IKEv2bis draft: IVs of retransmitted packets

2009-09-02 Thread Tero Kivinen
naoyoshi ueda writes: > According to ikev2bis-04 section 2.1: > > A retransmission from the initiator > > MUST be bitwise identical to the original request. That is, > > everything starting from the IKE Header (the IKE SA Initiator's SPI > > onwards) must be bitwise identical; items before

Re: [IPsec] Questions to IKEv2bis draft: IVs of retransmitted packets

2009-09-03 Thread Jeff Sun
All in all, the qualifications of being a true retransmitted IKE request/response message is dependent on the* post-encrypted* IKE request/response message being bitwise identical. Naoyoshi, if you don't mind me asking, which implementation are observing this behavior from (I'm not sure if this br

Re: [IPsec] Questions to IKEv2bis draft: IVs of retransmitted packets

2009-09-04 Thread naoyoshi ueda
Hello Tero, Thank you for your clear answer. It cleared up my questions. Thanks, Naoyoshi Ueda 2009/9/2 Tero Kivinen : > naoyoshi ueda writes: >> According to ikev2bis-04 section 2.1: >> >   A retransmission from the initiator >> >   MUST be bitwise identical to the original request.  That is, >

Re: [IPsec] Questions to IKEv2bis draft: IVs of retransmitted packets

2009-09-04 Thread naoyoshi ueda
Hello Jeff, Sorry, I withhold the product's name because of my business commitments. However, I just say that it is not an ordinary network device like VPN gateway. Regards, Naoyoshi Ueda 2009/9/3 Jeff Sun : > All in all, the qualifications of being a true retransmitted IKE > request/response m