[IPsec] Matching of IKE ID on certificate subject and RDN ordering

2020-05-10 Thread Tero Kivinen
Paul Wouters writes: > > Recently I had an interesting issue come up. I needed to generate a > certificate with a specific OU= content that our openssl/python > code couldn't do, and I switched to nss's cert-util to generate > a cert of sets for a test. > > Then I noticed something strange.

Re: [IPsec] Clarifications and Implementation Guidelines for using TCP Encapsulation in IKEv2 draft

2020-05-10 Thread Tero Kivinen
Benjamin Kaduk writes: > Sorry! I think that the current charter allows us to do an 8229bis > without additional rechartering. Good. I myself think it is better to do bis documents than just clarification guidelines as splitting things to multiple documents do make things harder to implement.