Hi, this version addresses comments from Derrell and incorporates PR with minor edits from Med. We also added a clarification about the influence of EAP-only authentication on this extension (thanks to Tobias Brunner who independently pointed out to this gap in the Security Considerations).
Regards, Chris & Valery. > Internet-Draft draft-ietf-ipsecme-ikev2-downgrade-prevention-07.txt is now > available. It is a work item of the IP Security Maintenance and Extensions > (IPSECME) WG of the IETF. > > Title: Downgrade Prevention for the Internet Key Exchange Protocol > Version 2 (IKEv2) > Authors: Valery Smyslov > Christopher Patton > Name: draft-ietf-ipsecme-ikev2-downgrade-prevention-07.txt > Pages: 14 > Dates: 2026-06-24 > > Abstract: > > This document describes an extension to the Internet Key Exchange > protocol version 2 (IKEv2) in which the peers authenticate the full > IKE_SA_INIT transcript. When both peers implement the extension and > at least one relevant authentication credential is not compromised, > this prevents certain downgrade attacks on IKEv2. > > This document updates RFC 7296. > > The IETF datatracker status page for this Internet-Draft is: > https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-downgrade-prevention/ > > There is also an HTMLized version available at: > https://datatracker.ietf.org/doc/html/draft-ietf-ipsecme-ikev2-downgrade-prevention-07 > > A diff from the previous version is available at: > https://author-tools.ietf.org/iddiff?url2=draft-ietf-ipsecme-ikev2-downgrade-prevention-07 > > Internet-Drafts are also available by rsync at: > rsync.ietf.org::internet-drafts > > > _______________________________________________ > IPsec mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
