Document: draft-mrose-rfc3288bis-01 Review: Lakshminath Dondeti Date: 11 maj 2005 Draft is ready to be published as Proposed Standard. ++++++++++++ Q: In Section 9, why is "must" in small case. Does it mean a "MUST"? Note: I have had a chance to take a peek at the tracker and have the following thoughts on Russ H.'s note on crypto algorithms: In the IPsec/IKEv2 world, the current crypto algorithms recommendations are as follows: 3DES-CBC is a MUST- (currently a MUST, but may no longer be the case in the future) and AES-CBC is a SHOULD+ (might soon take the place of MUST); similarly HMAC-MD5 is a MAY and HMAC-SHA-1 is a MUST. Within SASL, it appears that DIGEST-MD5 (HMAC-MD5) seems to be the choice even in the current I-Ds. The security ADs might have further insight into how to make these recommendations consistent across the IETF to the extent practical (backward compatibility etc.)