Re: [IPsec] Issue #26: Missing treatment of error cases

2009-09-30 Thread Tero Kivinen
Scott C Moonen writes: > Tero, I don't understand. Two weeks ago you said: > > If you use that kind of halfway up IKE SA for sending INFORMATIONAL > > message to other end (who thinks the IKE SA is up and valid), then I > > agree that sending both N(AUTHENTICATION_FAILED) and DELETE would be > > t

Re: [IPsec] #22 Simultaneous IKE SA rekey text

2009-09-30 Thread Tero Kivinen
David Wierbowski writes: > I agree with what you stated here, but I feel you are addressing something > that is not limited to a simultaneous rekey of the IKE SA. It deals with > any > rekey of an IKE SA. In my opinion the text is misplaced and should be in a > section that deals with handling of