Re: Re: Issue 254: Key Lifetime Issues
From: Jari Arkko (jari.arkkopiuha.net)
Date: Wed, 17 Nov 2004 03:33:00 -0500 (EST)
Bernard Aboba wrote:

[BA] How about if we delete this paragraph entirely?

Ok.


[BA] Actually the requirement is really support for resynchronization,
since it's possible to accomplish this without key lifetime negotiation
(e.g. IKEv2) How about this?

Change:

"Where TSKs are established as the result of a Secure Association
Protocol exchange, it is RECOMMENDED that the Secure Association
Protocol include secure negotiation of the TSK lifetime between the
peer and authenticator."

To:

"Where TSKs are established as the result of a Secure Association
Protocol exchange, it is RECOMMENDED that the Secure Association
Protocol include support for TSK resynchronization."

Sounds good. Thanks.


--Jari

Results generated by Tiger Technologies using MHonArc.