Hi Linda, thank you for your review. Please, see inline.
> Document: draft-ietf-ipsecme-ikev2-downgrade-prevention > Title: Downgrade Prevention for the Internet Key Exchange Protocol Version 2 > (IKEv2) Reviewer: Linda Dunbar Review result: Ready with Nits > > I am the assigned Gen-ART reviewer for this draft. The General Area > Review Team (Gen-ART) reviews all IETF documents being processed > by the IESG for the IETF Chair. Please treat these comments just > like any other last call comments. > > For more information, please see the FAQ at > > <https://wiki.ietf.org/en/group/gen/GenArtFAQ>. > > Document: draft-ietf-ipsecme-ikev2-downgrade-prevention-?? > Reviewer: Linda Dunbar > Review Date: 2026-06-12 > IETF LC End Date: 2026-06-12 > IESG Telechat date: Not scheduled for a telechat > > Summary: This draft updates IKEv2 by adding a negotiation signal and modified > AUTH transcript so both peers authenticate the same full IKE_SA_INIT > conversation, preventing attackers from silently downgrading the connection to > weaker key exchange methods or stripped extensions > > Major issues: None > > Minor issues: None > > Nits/editorial comments: > > - Section 6 says the responder includes the notification “regardless of > whether > it was received in the request or not,” and later says the modified > authentication calculation is used only if a peer both sent and received the > notification. Just wondering what to do when only one direction contains the > notification. Then the old logic (defined in Section 2.15 of RFC 7296) is used. > - Section 4: s/Having these preconditions the goal of the attacker is to > eavesdrop/Given these preconditions, the goal of the attacker is to eavesdrop/ > > - should expand PQ/T on the first use. Thanks, a PR is created: https://github.com/smyslov/ikev2-downgrade-prevention/pull/46 Regards, Valery. > > Best regards, > Linda Dunbar _______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
