Document: draft-ietf-ipsecme-ikev2-downgrade-prevention
Title: Downgrade Prevention for the Internet Key Exchange Protocol Version 2
(IKEv2) Reviewer: Linda Dunbar Review result: Ready with Nits

I am the assigned Gen-ART reviewer for this draft. The General Area
Review Team (Gen-ART) reviews all IETF documents being processed
by the IESG for the IETF Chair.  Please treat these comments just
like any other last call comments.

For more information, please see the FAQ at

<https://wiki.ietf.org/en/group/gen/GenArtFAQ>.

Document: draft-ietf-ipsecme-ikev2-downgrade-prevention-??
Reviewer: Linda Dunbar
Review Date: 2026-06-12
IETF LC End Date: 2026-06-12
IESG Telechat date: Not scheduled for a telechat

Summary: This draft updates IKEv2 by adding a negotiation signal and modified
AUTH transcript so both peers authenticate the same full IKE_SA_INIT
conversation, preventing attackers from silently downgrading the connection to
weaker key exchange methods or stripped extensions

Major issues: None

Minor issues: None

Nits/editorial comments:

- Section 6 says the responder includes the notification “regardless of whether
it was received in the request or not,” and later says the modified
authentication calculation is used only if a peer both sent and received the
notification. Just wondering what to do when only one direction contains the
notification.

- Section 4: s/Having these preconditions the goal of the attacker is to
eavesdrop/Given these preconditions, the goal of the attacker is to eavesdrop/

- should expand PQ/T on the first use.

Best regards,
Linda Dunbar


_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to