Re: [IPsec] FW: New Version Notification for draft-xu-erisav-00.txt and draft-xu-risav-00.txt

2022-09-19 Thread Michael Richardson
Paul Wouters wrote: > I am a bit confused why the source address needs to be cryptographically > verified to make SAV based decisions. What would be the scenarios of > inter AS communication where the packet is maliciously modified between > the two ASes but in such a way that

Re: [IPsec] FW: New Version Notification for draft-xu-erisav-00.txt and draft-xu-risav-00.txt

2022-09-19 Thread Paul Wouters
On Fri, 16 Sep 2022, guoyang...@zgclab.edu.cn wrote: Source Address Validation (SAV) is a problem that can be partially solved by using IPsec or other approaches. However, IPsec AH needs to hash the whole changeless fileds of the length-vairable packet and IPsec ESP needs to encrypt the whole