On Nov 21, 2018, at 23:00, Michael Richardson <[email protected]> wrote:
> Sadly, very few regular users use IPsec/IKEv2 for this kind of access. This is very incorrect. Almost all VPN providers for apple (OSX and iOS) use IKEv2 with CP. Based on numbers of concurrent users I have seen from some vendors using libreswan, we are talking in the orders of 100’s of thousands of users. And more and more Windows L2TP/IPsec and XAUTH deployments are moving to IKEv2. One of the main reasons: MOBIKE with phones using wifi and 4/5G and network switching. For Android, the situation is bad. Due to the OS not properly supporting IKEv2, most VPN services bundle openvpn apps for android and very few bundle strongswan with its userland ESP that can do IKEv2. > In almost all cases the VPN provider is in control of the software that is > installed on the client system, so they can hijack paypal already. This is also incorrect. All OSX and iOS provisioning happens via .mobileconfig profiles or apps using apple API’s that are equivalent. None of their apps can do weird things like hijacking paypal.com domain other then modifying the DNS stream after IPsec decryption. Any installed root CA as part of the VPN provisioning is limited to that VPN profile only and does not affect HTTPS. > Few support IPv6 or DNSSEC for the VPN either. That is correct but with SNAFUs like NAT64 breaking IPsec the telcos have helped greatly in that situation being addressed for IPv6. > > I think the document does a good job of making it clear that there > are issues the client implementer needs to worry about. > **** I have improved the text but I am waiting for my co-author to proofread and agree to my changes. It hopefully addresses Warrens concerns as best we can. > But, this seems terribly unlikely since just getting two VPNs installed > (and compatible) and running at the same time is such deep VPN-fu, that it's > like only half the IPsec WG members that could ever make this work anyway. It is currently uncommon indeed but I think and hope we will see more of this, especially when we all want a continuous VPN link up to our home network. Paul _______________________________________________ IPsec mailing list [email protected] https://www.ietf.org/mailman/listinfo/ipsec
