Hi,

a new (-01) version of IKE_AUX draft is just posted.

Changes from -00 version:
1. Authentication of IKE_AUX messages is completely rewritten 
    based on recent discussions in the WG. More details
    are provided regarding selecting keys for authentication
    and for message protection.

2. As a result of changing a way the messages are authenticated
    the restrictions on using IKE fragmentation are lifted and 
    the correspondent section is deleted.

3. Some words are added regarding handling errors in IKE_AUX.

4. Security considerations are updated based on recent discussion
     in the WG.

5. Editorial nits.

I still stick with IKE_AUX name for now waiting for more suggestions from 
people who find this name confusing...

Regards,
Valery.


-----Original Message-----
From: [email protected] [mailto:[email protected]] 
Sent: Friday, July 27, 2018 6:05 PM
To: Valery Smyslov
Subject: New Version Notification for draft-smyslov-ipsecme-ikev2-aux-01.txt


A new version of I-D, draft-smyslov-ipsecme-ikev2-aux-01.txt
has been successfully submitted by Valery Smyslov and posted to the
IETF repository.

Name:           draft-smyslov-ipsecme-ikev2-aux
Revision:       01
Title:          Auxiliary Exchange in the IKEv2 Protocol
Document date:  2018-07-27
Group:          Individual Submission
Pages:          9
URL:            
https://www.ietf.org/internet-drafts/draft-smyslov-ipsecme-ikev2-aux-01.txt
Status:         
https://datatracker.ietf.org/doc/draft-smyslov-ipsecme-ikev2-aux/
Htmlized:       https://tools.ietf.org/html/draft-smyslov-ipsecme-ikev2-aux-01
Htmlized:       
https://datatracker.ietf.org/doc/html/draft-smyslov-ipsecme-ikev2-aux
Diff:           
https://www.ietf.org/rfcdiff?url2=draft-smyslov-ipsecme-ikev2-aux-01

Abstract:
   This documents defines a new exchange, called Auxiliary Exchange, for
   the Internet Key Exchange protocol Version 2 (IKEv2).  This exchange
   can be used for transferring large amount of data in the process of
   IKEv2 Security Association (SA) establishment.  Introducing Auxiliary
   Exchange allows to re-use existing IKE Fragmentation mechanism, that
   helps to avoid IP fragmentation of large IKE messages, but cannot be
   used in the initial IKEv2 exchange.

                                                                                
  


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat

_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to