Re: [IPsec] New I-D on IKEv3

2012-10-18 Thread Yoav Nir
On Oct 18, 2012, at 2:26 AM, Dan Harkins wrote: Hi David, On Wed, October 17, 2012 11:36 am, David Brownhill (dbrownhi) wrote: Hi Dan, The lack or EAP authentication would be a non-starter for us to implement this in our remote access VPN client. Why not support EAP authentication?

[IPsec] Call for agenda items

2012-10-18 Thread Tero Kivinen
Paul Hoffman writes: Greetings again. We have a 2-hour time slot in Atlanta, which is way more than we asked for. We don't need to be talking about draft-ietf-ipsecme-p2p-vpn-problem because it's finished with WG LC and is being sent to the AD for review. This is a call for agenda items.

Re: [IPsec] brainpool summary, suggested way ahead, and comments on draft

2012-10-18 Thread Sean Turner
Dan, There's not need to ask the IESG about the process to update the registry in question it's clear: RFC required. You can get an RFC through a WG, through an AD, or through the ISE. spt On 10/15/12 10:54 PM, Dan Harkins wrote: Hi Sean, On Mon, October 15, 2012 5:00 pm, Sean Turner

Re: [IPsec] brainpool summary, suggested way ahead, and comments on draft

2012-10-18 Thread Sean Turner
Dan, After talking it over the preferred* approach to answer the 802.11 request is to include them in the IKEv1 registry (as suggested by Michael R.) with a tweaked note. Rationale being that if you used what I suggested you'd have to make sure two registries were updated if a change was

Re: [IPsec] STRONG NUDGE: Revised AD VPN Requirements

2012-10-18 Thread Ulliott, Chris
For my scenario, having hub and spoke doesn't really work. What happens with multiple organisations, do they each have a hub? - how do they communicate between them. I'd like to set the challenge of trying to do full mesh - it may be that we need a mechanism that notifies gateways if one has

Re: [IPsec] New Version Notification for draft-kivinen-ipsecme-oob-pubkey-01.txt

2012-10-18 Thread Sean Turner
Tero, Gotta ask: Should this draft update RFC 5996? On the one hand, it's optional and existing implementations don't need to support it. On the other hand, if you're really trying to deprecate the old RSA raw key format shouldn't it update the base doc? Could add an informative reference

[IPsec] Waiting for new version of draft-ietf-ipsecme-ad-vpn-problem

2012-10-18 Thread Paul Hoffman
On Oct 18, 2012, at 6:31 AM, Tero Kivinen kivi...@iki.fi wrote: I did send quite a lot of comments to the draft at 2012-09-10, and I have not seen those taken into the draft yet. Also as I noted in my email I am quite sure we are still missing some requirements, but as the current document is

Re: [IPsec] Call for agenda items

2012-10-18 Thread Paul Hoffman
On Oct 17, 2012, at 5:32 PM, Dan Harkins dhark...@lounge.org wrote: I would be happy to discuss IKEv3. Please let me know if you'll put me on the agenda and I'll prepare some slides to talk to. It would be good if you put together a short (less than 15 minutes) presentation on your