Cloning the IKE Security Association in the Internet Key Exchange Protocol Version 2 (IKEv2)
draft-mglt-ipsecme-clone-ike-sa-09
Revision differences
Document history
Date | Rev. | By | Action |
---|---|---|---|
2016-03-02
|
09 | (System) | RFC Editor state changed to AUTH48-DONE from AUTH48 |
2016-02-23
|
09 | (System) | RFC Editor state changed to AUTH48 from RFC-EDITOR |
2016-02-22
|
09 | Jean Mahoney | Closed request for Telechat review by GENART with state 'No Response' |
2016-02-09
|
09 | (System) | RFC Editor state changed to RFC-EDITOR from EDIT |
2015-12-10
|
09 | (System) | RFC Editor state changed to EDIT |
2015-12-10
|
09 | (System) | IESG state changed to RFC Ed Queue from Approved-announcement sent |
2015-12-10
|
09 | (System) | Announcement was received by RFC Editor |
2015-12-07
|
09 | (System) | IANA Action state changed to RFC-Ed-Ack from Waiting on RFC Editor |
2015-12-07
|
09 | (System) | IANA Action state changed to Waiting on RFC Editor from Waiting on Authors |
2015-12-07
|
09 | (System) | IANA Action state changed to Waiting on Authors from In Progress |
2015-12-07
|
09 | (System) | IANA Action state changed to In Progress |
2015-12-07
|
09 | Amy Vezza | IESG state changed to Approved-announcement sent from Approved-announcement to be sent::Point Raised - writeup needed |
2015-12-07
|
09 | Amy Vezza | IESG has approved the document |
2015-12-07
|
09 | Amy Vezza | Closed "Approve" ballot |
2015-12-07
|
09 | Amy Vezza | Ballot approval text was generated |
2015-12-07
|
09 | Amy Vezza | Ballot writeup was changed |
2015-12-04
|
09 | Gunter Van de Velde | Closed request for Last Call review by OPSDIR with state 'No Response' |
2015-12-03
|
09 | Daniel Migault | New version available: draft-mglt-ipsecme-clone-ike-sa-09.txt |
2015-12-03
|
08 | Cindy Morgan | IESG state changed to Approved-announcement to be sent::Point Raised - writeup needed from IESG Evaluation |
2015-12-03
|
08 | Daniel Migault | New version available: draft-mglt-ipsecme-clone-ike-sa-08.txt |
2015-12-03
|
07 | Valery Smyslov | IANA Review state changed to Version Changed - Review Needed from IANA OK - Actions Needed |
2015-12-03
|
07 | Valery Smyslov | New version available: draft-mglt-ipsecme-clone-ike-sa-07.txt |
2015-12-03
|
06 | Spencer Dawkins | [Ballot Position Update] New position, No Objection, has been recorded for Spencer Dawkins |
2015-12-03
|
06 | Jari Arkko | [Ballot Position Update] New position, No Objection, has been recorded for Jari Arkko |
2015-12-02
|
06 | Joel Jaeggli | [Ballot comment] needs an editorial scrub for clarity, bens review is spot on. |
2015-12-02
|
06 | Joel Jaeggli | [Ballot Position Update] New position, No Objection, has been recorded for Joel Jaeggli |
2015-12-02
|
06 | Terry Manderson | [Ballot Position Update] New position, No Objection, has been recorded for Terry Manderson |
2015-12-02
|
06 | Barry Leiba | [Ballot Position Update] New position, No Objection, has been recorded for Barry Leiba |
2015-12-02
|
06 | Stephen Farrell | [Ballot comment] - General: What'd happen if I used MPTCP with this? In particular with the multiple client i/f version. It should work I guess … [Ballot comment] - General: What'd happen if I used MPTCP with this? In particular with the multiple client i/f version. It should work I guess but I wonder if anyone's thought about any corner case issues (e.g. timing) that might come up? - section 4: "would be deleted" is too vague really - what did you want to see happen? - section 2: I don't get the last paragraph. What's that mean? nits: - General: There are many minor grammatical issues, e.g. cases of missing "an" or "the." It'd be nice to fix those before the RFC editor has to. - section 2: typo: "with with" |
2015-12-02
|
06 | Stephen Farrell | [Ballot Position Update] New position, No Objection, has been recorded for Stephen Farrell |
2015-12-02
|
06 | Alia Atlas | [Ballot Position Update] New position, No Objection, has been recorded for Alia Atlas |
2015-12-02
|
06 | Cindy Morgan | Changed consensus to Yes from Unknown |
2015-12-01
|
06 | Ben Campbell | [Ballot Position Update] Position for Ben Campbell has been changed to No Objection from No Record |
2015-12-01
|
06 | Ben Campbell | [Ballot comment] I don't have any substantive comments, but do have a number of editorial comments: - Abstract: -- The abstract seems unnecessarily long, can … [Ballot comment] I don't have any substantive comments, but do have a number of editorial comments: - Abstract: -- The abstract seems unnecessarily long, can it be edited down? I suggest moving most of the text into the introduction and creating a much shorter abstract. -- 2nd paragraph, second sentence: "... using multiple interfaces requires to set up an IKE SA..." There appears to be a missing word after "requires". That is, requires _what_ to set up the SA? (Alternately, "...requires an IKE SA to be set up...") -- Please expand MOBIKE on first use (both in the abstract and in the body). - Section 2, 2nd paragraph after Figure 3: -- s/"In case of IPsec it means..."/"In the case of IPSEC, this means..." -- s/"drawback of such approach"/"drawback of such an approach" -- What does "transactionally" mean in context of "transactionally synchronized"? Is that different than just "synchronized"? -- s/"The drawback of such approach is that it requires new IKE SA"/"The drawback of such _an_approach is that it requires new IKE SA" - 2, third paragraph from end: "the VPN End User and the Security Gateway wants to move" s/wants/want -4, first paragraph: -- The language "The goal of the document..." makes it sound like there is a chance the document might fail to achieve the goal. I assume that is not the intent. I suggest reformulating along the lines of "This document specifies..." -- "without performing an authentication." without performing a _new_ authentication? - 5.2, 2nd paragraph from end: I don't understand the phrase "If the CREATE_CHILD_SA request concerns an IKE SA rekey ..." Maybe s/concerns/requests? -5.3, 4th paragraph: s/"In some cases responder..."/"In some cases, the responder..." - 8, third paragraph: Does this talk about resource exhaustion in general, or a resource exhaustion _attack_? |
2015-12-01
|
06 | Ben Campbell | Ballot comment text updated for Ben Campbell |
2015-12-01
|
06 | Benoît Claise | [Ballot Position Update] New position, No Objection, has been recorded for Benoit Claise |
2015-11-30
|
06 | Alvaro Retana | [Ballot Position Update] New position, No Objection, has been recorded for Alvaro Retana |
2015-11-30
|
06 | Deborah Brungard | [Ballot Position Update] New position, No Objection, has been recorded for Deborah Brungard |
2015-11-25
|
06 | Jean Mahoney | Request for Telechat review by GENART is assigned to Joel Halpern |
2015-11-25
|
06 | Jean Mahoney | Request for Telechat review by GENART is assigned to Joel Halpern |
2015-11-18
|
06 | Kathleen Moriarty | IESG state changed to IESG Evaluation from Waiting for Writeup |
2015-11-18
|
06 | (System) | IANA Review state changed to IANA OK - Actions Needed from Version Changed - Review Needed |
2015-11-17
|
06 | Kathleen Moriarty | Ballot has been issued |
2015-11-17
|
06 | Kathleen Moriarty | [Ballot Position Update] New position, Yes, has been recorded for Kathleen Moriarty |
2015-11-17
|
06 | Kathleen Moriarty | Created "Approve" ballot |
2015-11-17
|
06 | Kathleen Moriarty | Ballot writeup was changed |
2015-11-17
|
06 | Kathleen Moriarty | Placed on agenda for telechat - 2015-12-03 |
2015-11-12
|
06 | Tero Kivinen | Request for Last Call review by SECDIR Completed: Ready. Reviewer: Alexey Melnikov. |
2015-10-27
|
06 | Cindy Morgan | IANA Review state changed to Version Changed - Review Needed from IANA OK - Actions Needed |
2015-10-27
|
06 | Cindy Morgan | New version available: draft-mglt-ipsecme-clone-ike-sa-06.txt |
2015-10-27
|
05 | Amanda Baber | IANA Review state changed to IANA OK - Actions Needed from IANA - Not OK |
2015-10-27
|
05 | (System) | IESG state changed to Waiting for Writeup from In Last Call |
2015-10-25
|
05 | (System) | IANA Review state changed to IANA - Not OK from IANA - Review Needed |
2015-10-25
|
05 | Amanda Baber | (Via drafts-lastcall@iana.org): IESG/Authors/WG Chairs: IANA has completed its review of draft-mglt-ipsecme-clone-ike-sa-05. If any part of this review is inaccurate, please let us know. IANA … (Via drafts-lastcall@iana.org): IESG/Authors/WG Chairs: IANA has completed its review of draft-mglt-ipsecme-clone-ike-sa-05. If any part of this review is inaccurate, please let us know. IANA understands that, upon approval of this document, there is a single action which must be completed. In the IKEv2 Notify Message Types - Status Types subregistry of the Internet Key Exchange Version 2 (IKEv2) Parameters registry located at: http://www.iana.org/assignments/ikev2-parameters/ two new status types are to be registered as follows: Value: [ TBD-at-Registration ] NOTIFY MESSAGES - STATUS TYPES: CLONE_IKE_SA_SUPPORTED Reference: [ RFC-to-be ] Value: [ TBD-at-Registration ] NOTIFY MESSAGES - STATUS TYPES: CLONE_IKE_SA Reference: [ RFC-to-be ] We've asked the IESG-designated expert for the registry to review and approve these registrations. As the registration procedure for IKEv2 Notify Message Types - Status Types is "Expert Review," as defined by RFC 5226, we can't complete this action without his approval. Note: The actions requested in this document will not be completed until the document has been approved for publication as an RFC. This message is only to confirm what actions will be performed. |
2015-10-14
|
05 | (System) | Notify list changed from daniel.migault@ericsson.com, draft-mglt-ipsecme-clone-ike-sa.ad@ietf.org, svan@elvis.ru, kivinen@iki.fi, draft-mglt-ipsecme-clone-ike-sa.shepherd@ietf.org, draft-mglt-ipsecme-clone-ike-sa@ietf.org to (None) |
2015-10-09
|
05 | Gunter Van de Velde | Request for Last Call review by OPSDIR is assigned to Lionel Morand |
2015-10-09
|
05 | Gunter Van de Velde | Request for Last Call review by OPSDIR is assigned to Lionel Morand |
2015-10-01
|
05 | Jean Mahoney | Request for Last Call review by GENART is assigned to Joel Halpern |
2015-10-01
|
05 | Jean Mahoney | Request for Last Call review by GENART is assigned to Joel Halpern |
2015-10-01
|
05 | Tero Kivinen | Request for Last Call review by SECDIR is assigned to Alexey Melnikov |
2015-10-01
|
05 | Tero Kivinen | Request for Last Call review by SECDIR is assigned to Alexey Melnikov |
2015-09-29
|
05 | Amy Vezza | IANA Review state changed to IANA - Review Needed |
2015-09-29
|
05 | Amy Vezza | The following Last Call announcement was sent out: From: The IESG To: IETF-Announce Reply-To: ietf@ietf.org Sender: Subject: Last Call: (Cloning IKE SA in the Internet … The following Last Call announcement was sent out: From: The IESG To: IETF-Announce Reply-To: ietf@ietf.org Sender: Subject: Last Call: (Cloning IKE SA in the Internet Key Exchange Protocol Version 2 (IKEv2)) to Proposed Standard The IESG has received a request from an individual submitter to consider the following document: - 'Cloning IKE SA in the Internet Key Exchange Protocol Version 2 (IKEv2)' as Proposed Standard The IESG plans to make a decision in the next few weeks, and solicits final comments on this action. Please send substantive comments to the ietf@ietf.org mailing lists by 2015-10-27. Exceptionally, comments may be sent to iesg@ietf.org instead. In either case, please retain the beginning of the Subject line to allow automated sorting. Abstract This document considers a VPN End User establishing an IPsec SA with a Security Gateway using the Internet Key Exchange Protocol Version 2 (IKEv2), where at least one of the peers has multiple interfaces or where Security Gateway is a cluster with each node having its own IP address. With the current IKEv2 protocol, the outer IP addresses of the IPsec SA are determined by those used by IKE SA. As a result using multiple interfaces requires to set up an IKE SA on each interface, or on each path if both the VPN Client and the Security Gateway have multiple interfaces. Setting each IKE SA involves authentications which might require multiple round trips as well as activity from the VPN End User and thus would delay the VPN establishment. In addition multiple authentications unnecessarily increase the load on the VPN client and the authentication infrastructure. This document presents the solution that allows to clone IKEv2 SA, where an additional SA is derived from an existing one. The newly created IKE SA is set without the IKEv2 authentication exchange. This IKE SA can later be assigned to another interface or moved to another cluster mode using MOBIKE protocol. The file can be obtained via https://datatracker.ietf.org/doc/draft-mglt-ipsecme-clone-ike-sa/ IESG discussion can be tracked via https://datatracker.ietf.org/doc/draft-mglt-ipsecme-clone-ike-sa/ballot/ No IPR declarations have been submitted directly on this I-D. |
2015-09-29
|
05 | Amy Vezza | IESG state changed to In Last Call from Last Call Requested |
2015-09-29
|
05 | Kathleen Moriarty | Last call was requested |
2015-09-29
|
05 | Kathleen Moriarty | Ballot approval text was generated |
2015-09-29
|
05 | Kathleen Moriarty | Ballot writeup was generated |
2015-09-29
|
05 | Kathleen Moriarty | IESG state changed to Last Call Requested from Publication Requested |
2015-09-29
|
05 | Kathleen Moriarty | Last call announcement was generated |
2015-09-29
|
05 | Kathleen Moriarty | Last call announcement was generated |
2015-09-29
|
05 | Kathleen Moriarty | IESG process started in state Publication Requested |
2015-09-29
|
05 | Kathleen Moriarty | Notification list changed to daniel.migault@ericsson.com, draft-mglt-ipsecme-clone-ike-sa.ad@ietf.org, svan@elvis.ru, kivinen@iki.fi, draft-mglt-ipsecme-clone-ike-sa.shepherd@ietf.org, draft-mglt-ipsecme-clone-ike-sa@ietf.org from "Tero Kivinen" <kivinen@iki.fi> |
2015-09-29
|
05 | Tero Kivinen | Changed document writeup |
2015-09-14
|
05 | Kathleen Moriarty | Shepherding AD changed to Kathleen Moriarty |
2015-09-14
|
05 | Kathleen Moriarty | Stream changed to IETF from None |
2015-09-14
|
05 | Kathleen Moriarty | Intended Status changed to Proposed Standard from None |
2015-09-14
|
05 | Kathleen Moriarty | Notification list changed to "Tero Kivinen" <kivinen@iki.fi> |
2015-09-14
|
05 | Kathleen Moriarty | Document shepherd changed to Tero Kivinen |
2015-08-24
|
05 | Daniel Migault | New version available: draft-mglt-ipsecme-clone-ike-sa-05.txt |
2015-03-04
|
04 | Daniel Migault | New version available: draft-mglt-ipsecme-clone-ike-sa-04.txt |
2015-01-19
|
03 | Valery Smyslov | New version available: draft-mglt-ipsecme-clone-ike-sa-03.txt |
2014-07-21
|
02 | Daniel Migault | New version available: draft-mglt-ipsecme-clone-ike-sa-02.txt |
2014-03-13
|
01 | Daniel Migault | New version available: draft-mglt-ipsecme-clone-ike-sa-01.txt |
2014-02-13
|
00 | Daniel Migault | New version available: draft-mglt-ipsecme-clone-ike-sa-00.txt |