Document: draft-ietf-ipsecme-ikev2-pqc-auth Title: Signature Authentication in the Internet Key Exchange Version 2 (IKEv2) using PQC Reviewer: Gyan Mishra Review result: Almost Ready
I am the assigned Gen-ART reviewer for this draft. The General Area Review Team (Gen-ART) reviews all IETF documents being processed by the IESG for the IETF Chair. Please treat these comments just like any other last call comments. For more information, please see the FAQ at <https://wiki.ietf.org/en/group/gen/GenArtFAQ>. Document: draft-ietf-ipsecme-ikev2-pqc-auth-?? Reviewer: Gyan Mishra Review Date: 2026-07-19 IETF LC End Date: 2026-07-31 IESG Telechat date: Not scheduled for a telechat Summary: Signature-based authentication methods are utilized in the Internet Key Exchange Version 2 (IKEv2). The current version of the IKEv2 protocol, specified in RFC 7296, supports traditional digital signatures. This document specifies a generic mechanism for integrating post-quantum cryptographic (PQC) digital signature algorithms into the IKEv2 protocol. The approach allows for seamless inclusion of any PQC signature scheme within the existing authentication framework of IKEv2. Additionally, it outlines how Module-Lattice-Based Digital Signatures (ML-DSA) and Stateless Hash-Based Digital Signatures (SLH-DSA), can be employed as authentication methods within the IKEv2 protocol, as they have been standardized by US NIST. I believe this specification is almost ready for publication. One question I would like to ask the authors is related to any IANA code points for the use of PQC for signature for IKEv2. As this is standards track and a significant change to IKEv2 which does impact all IPSEC implementations vendors supporting the PQM update feature. To ensure standardization and forward and backward compatibility in the implementation should there be a standard codepoint allocated for the drafts update to IKEv2 for PQM signature signing. What is the impact on SA security association rekeying during key update intervals. I do not see anything mentioned related but as we are using a new PQM signing mechanism, I wonder if there is any impact and if so it should be added to the considerations section. Major issues: None Minor issues: None Nits/editorial comments: None _______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
