Hi,
a new (-01) version of IKE_AUX draft is just posted.
Changes from -00 version:
1. Authentication of IKE_AUX messages is completely rewritten
based on recent discussions in the WG. More details
are provided regarding selecting keys for authentication
and for message protection.
2. As a result of changing a way the messages are authenticated
the restrictions on using IKE fragmentation are lifted and
the correspondent section is deleted.
3. Some words are added regarding handling errors in IKE_AUX.
4. Security considerations are updated based on recent discussion
in the WG.
5. Editorial nits.
I still stick with IKE_AUX name for now waiting for more suggestions from
people who find this name confusing...
Regards,
Valery.
-----Original Message-----
From: [email protected] [mailto:[email protected]]
Sent: Friday, July 27, 2018 6:05 PM
To: Valery Smyslov
Subject: New Version Notification for draft-smyslov-ipsecme-ikev2-aux-01.txt
A new version of I-D, draft-smyslov-ipsecme-ikev2-aux-01.txt
has been successfully submitted by Valery Smyslov and posted to the
IETF repository.
Name: draft-smyslov-ipsecme-ikev2-aux
Revision: 01
Title: Auxiliary Exchange in the IKEv2 Protocol
Document date: 2018-07-27
Group: Individual Submission
Pages: 9
URL:
https://www.ietf.org/internet-drafts/draft-smyslov-ipsecme-ikev2-aux-01.txt
Status:
https://datatracker.ietf.org/doc/draft-smyslov-ipsecme-ikev2-aux/
Htmlized: https://tools.ietf.org/html/draft-smyslov-ipsecme-ikev2-aux-01
Htmlized:
https://datatracker.ietf.org/doc/html/draft-smyslov-ipsecme-ikev2-aux
Diff:
https://www.ietf.org/rfcdiff?url2=draft-smyslov-ipsecme-ikev2-aux-01
Abstract:
This documents defines a new exchange, called Auxiliary Exchange, for
the Internet Key Exchange protocol Version 2 (IKEv2). This exchange
can be used for transferring large amount of data in the process of
IKEv2 Security Association (SA) establishment. Introducing Auxiliary
Exchange allows to re-use existing IKE Fragmentation mechanism, that
helps to avoid IP fragmentation of large IKE messages, but cannot be
used in the initial IKEv2 exchange.
Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.
The IETF Secretariat
_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec