Re: [IPsec] Issue #202: Token makers generating the same tokens without synchronized DB

2011-01-11 Thread David Wierbowski
I agree with Tero that it is unsafe to assume how a load balancer decides to distribute traffic. Since section 9.4 (previously 10.4) is in the Security Considerations section it seems reasonable to me that we'd warn that the algorithms in 5.1 and 5.2 should not be used in cases where load balancin

Re: [IPsec] Issue #202: Token makers generating the same tokens without synchronized DB

2011-01-11 Thread Paul Hoffman
On 1/10/11 12:03 AM, Yoav Nir wrote: Greetings. We have just submitted version -03 of the draft. This closes issues, #198, #199, #200, and #201. Which leaves us with just one issue: #202 So far, there have been no posts on this thread. I encourage the document authors to weigh in on the to