secdir review of draft-ietf-msec-ipsec-group-counter-modes

2010-07-14 Thread Sam Hartman
This is a secdir review of the above draft. The text looks fine. However, I'm concerned that this specification does not provide sufficient detail for interoperable implementation. It makes it clear that a GKMS needs to allocate SIDs but does not cite any mechanism for a GKMS to do so. I think

Re: [secdir] secdir review of draft-ietf-msec-ipsec-group-counter-modes

2010-07-15 Thread Brian Weis
Hi Sam, Thanks for your review. On Jul 14, 2010, at 4:55 AM, Sam Hartman wrote: This is a secdir review of the above draft. The text looks fine. However, I'm concerned that this specification does not provide sufficient detail for interoperable implementation. It makes it clear that a G

Re: [secdir] secdir review of draft-ietf-msec-ipsec-group-counter-modes

2010-07-15 Thread Sam Hartman
> "Brian" == Brian Weis writes: Brian> There is an I-D for one GKMS (draft-ietf-msec-gdoi-update-06) Brian> that includes support for SIDs which could be referenced. It Brian> is expected to head to WGLC soon. Would citing that document Brian> address your concern? A normativ