Re: [IPsec] AD review of draft-ietf-ipsecme-ikev2-multiple-ke-06

2022-10-01 Thread Andreas Steffen
implementation with which strongSwan has been successfully interoperating is ELVIS by Valery Smyslov . Best regards Andreas == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN

Re: [IPsec] WG adoptation call for draft-smyslov-ipsecme-ikev2-aux-02

2019-03-20 Thread Andreas Steffen
next week > (2019-03-22). > > If you have any reasons why this should not be adopted as WG document, > send email to the list as soon as possible. ========== Andreas Steffen andreas.stef...@strongswan.org

Re: [IPsec] Protocol Action: 'Using Edwards-curve Digital Signature Algorithm (EdDSA) in the Internet Key Exchange (IKEv2)' to Proposed Standard (draft-ietf-ipsecme-eddsa-04.txt)

2018-02-26 Thread Andreas Steffen
Hi, strongSwan also has a working implementation of Ed25519. Regards Andreas On 26.02.2018 18:01, The IESG wrote: >Apple reports a working implementation. == Andreas Steffen andreas.s

Re: [IPsec] Working group last call for the draft-nir-ipsecme-eddsa-00

2017-02-15 Thread Andreas Steffen
ld be able to release the stable version as soon as the code point has been assigned. Best regards Andreas Steffen On 09.02.2017 13:40, Tero Kivinen wrote: > Ah I noticed that my last call email had wrong draft name in the > subject line and in the link. The correct draft name is of course >

[IPsec] NewHope Post-Quantum Key Exchange for IKE

2016-10-24 Thread Andreas Steffen
4000 bytes but with IKEv2 fragmentation in place they do not pose any problems. Best regards Andreas Steffen BTW - As soon as the Safecurves RFC number will be known, a strongSwan version with Curve25519 support will b

Re: [IPsec] Call for adoption: draft-nir-ipsecme-curve25519 as a WG work item

2015-08-28 Thread Andreas Steffen
Hi Paul, I'm in favour of adopting this document. Best regards Andreas Steffen On 25.08.2015 00:58, Paul Hoffman wrote: Greetings. There was some general interest in having a standard way to modern elliptic curves for ephemeral key exchange. Please respond in this thread whether or no you

Re: [IPsec] PSK mode

2015-08-20 Thread Andreas Steffen
payloads not to cause fragmentation); we could negotiate NTRU as yet another 'DH group'. That way, we don't need to have this as a separate option to be negotiated. == Andreas Steffen andreas.stef

Re: [IPsec] IKE daemon supporting twofish and serpent for IKE?

2015-05-26 Thread Andreas Steffen
for IKE (not ESP) ? I only know of libreswan/openswan, but I would like to do a real interop test with another implementation. This would be using the private numbers 65004/65005 ? Paul == Andreas Steffen

Re: [IPsec] AD VPN: protocol selection

2013-12-04 Thread Andreas Steffen
://tools.ietf.org/html/draft-brunner-ikev2-mediation-00 == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies

Re: [IPsec] Other documents to upgrade to internet standard

2013-11-12 Thread Andreas Steffen
Cisco, Juniper and Check Point support them, as well as both StrongSwan and OpenSwan. I'm sure there are others as well. Yoav == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source

[IPsec] Approve

2013-05-16 Thread Andreas Steffen
Hi list, I approve of using draft-smyslov-ipsecme-ikev2-fragmentation as a starting for IKEv2 fragmentation. Regards Andreas == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open

Re: [IPsec] Clarification on identities involved in IKEv2 EAPauthentication

2009-11-10 Thread Andreas Steffen
Have a look at the following Windows 7 IKEv2 HOWTO: http://wiki.strongswan.org/wiki/strongswan/Windows7 Best regards Andreas Steffen shaik abdulla wrote: Hi, Is there any windows API for IKEV2.If so please send me link