@@ -196,7 +196,7 @@ To disable sequence numbering, and thus replay protection based on
196
196
sequence numbers, the initiator MUST propose SN=None (TBD10). When the
197
197
sequence numbers are disabled, there won't be any SN in the
198
198
EESP packet, the receiver SHOULD NOT dynamically modify ports or
199
- addresses without using IKEv2 Mobility [RFC4555].
199
+ addresses without using IKEv2 Mobility [[ RFC4555] ].
200
200
201
201
Because the Replay Protection service is disabled, an attacker can re
202
202
play packets with a different source address. Such an attacker could
@@ -417,8 +417,9 @@ INVALID_SESSION_ID error message, indicating a supported value.
417
417
UDP encapsulation for EESP is largely similar to the ESP UDP
418
418
encapsulation specified in [[RFC3948]], with the primary difference
419
419
being the UDP source port used by the EESP Sub SA may be different
420
- from IKE_SA source port.for more flexible handling of EESP traffic,
421
- particularly ECMP support along the path and in the NIC.
420
+ from IKE_SA source port, as specified in [[RFC3947]], for more
421
+ flexible handling of EESP traffic, particularly ECMP support
422
+ along the path and in the NIC.
422
423
423
424
A receiver indenting to support both ESP and EESP encapsulated in UDP
424
425
must start ESP SPI, most significant bit of the SPI, with zero.
608
609
** RFC8750
609
610
** RFC4555
610
611
611
- ** I-D.irtf-cfrg-kangarootwelve
612
612
** I-D.mrossberg-ipsecme-multiple-sequence-counters
613
613
** I-D.ponchon-ipsecme-anti-replay-subspaces
614
614
** I-D.ietf-ipsecme-g-ikev2
655
655
:REF_ORG: IANA
656
656
:END:
657
657
658
- ** NIST800-185
659
- :PROPERTIES:
660
- :REF_TARGET: https://csrc.nist.gov/pubs/sp/800/185/final
661
- :REF_TITLE: SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash and ParallelHash
662
- :REF_ORG: NIST
663
- :END:
664
-
665
- ** Keccak-vs-AES
666
- :PROPERTIES:
667
- :REF_TARGET: https://cryptography.gmu.edu/athena/papers/GMU_DATE_2015.pdf
668
- :REF_TITLE: Comparison of Multi-Purpose Cores of Keccak and AES
669
- :REF_ORG: NIST
670
- :END:
671
658
672
659
* Additional Stuff
673
660
0 commit comments