Re: [IPsec] Comments to draft-nir-ipsecme-cafr-02

2013-10-11 Thread Yoav Nir
On Oct 9, 2013, at 2:10 PM, Tero Kivinen wrote: > In section "2.2. Verifying the HAND_OVER_CHILD_SAS Notification" the > document lists operations which needs to be done when handling the > notification. The process seems otherwise quite good, expect the error > handling seems to be bit drastic.

Re: [IPsec] Update to RFC4307 too?

2013-10-11 Thread Paul Wouters
On Wed, 9 Oct 2013, Tero Kivinen wrote: I think the changes we would like to do there are: Downgrade Diffie-Hellman group 2 (1024-bits) from MUST- to SHOULD. Actually, 4307 states: 3.1.2. Diffie-Hellman Groups There are several Modular Exponential (MODP) groups that are defined for u