Last Call: <draft-ietf-ipsecme-ikev2-pqc-auth-09.txt> (Signature Authentication in the Internet Key Exchange Version 2 (IKEv2) using PQC) to Proposed Standard

The IESG <iesg-secretary@ietf.org> Fri, 10 July 2026 15:50 UTC

Return-Path: <iesg-secretary@ietf.org>
X-Original-To: ietf-announce@ietf.org
Delivered-To: ietf-announce@mail2.ietf.org
Received: from [10.244.22.19] (gaia.k8s.ietf.org [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id A16B71149F863; Fri, 10 Jul 2026 08:50:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783698648; bh=Y/WRAHhGRgf/ghcpWJsv6X6xOOXIhL+i9Fo7vp/l7Ig=; h=From:To:Subject:CC:Reply-To:Date; b=xOIOD57dsImWZGhnj8TGZUdox2T+MnA1AeBEbsOCI5l1YzstuTgXywaIaVcJIAMeo OCxPH1RVhxFdHi3yIezoxqjbpgyLh9WGXv67WYyFIdqwSqrsLNcKnSe2OjNkXOAOU7 G5D/5GJP4MJyNRzeWw+el6tDq/d9FbPVARlJSzHU=
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
Subject: Last Call: <draft-ietf-ipsecme-ikev2-pqc-auth-09.txt> (Signature Authentication in the Internet Key Exchange Version 2 (IKEv2) using PQC) to Proposed Standard
X-Test-IDTracker: no
X-IETF-IDTracker: 12.69.0
Auto-Submitted: auto-generated
Precedence: bulk
Sender: iesg-secretary@ietf.org
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <178369864860.960.14154708875928377731@dt-datatracker-d4d6ff9d9-x8khv>
Date: Fri, 10 Jul 2026 08:50:48 -0700
Message-ID-Hash: VMN3UWRTWDVKUHFJMME3AOAZDIPY5ZAI
X-Message-ID-Hash: VMN3UWRTWDVKUHFJMME3AOAZDIPY5ZAI
X-MailFrom: iesg-secretary@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ietf-announce.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-ipsecme-ikev2-pqc-auth@ietf.org, ipsec@ietf.org, ipsecme-chairs@ietf.org, kivinen@iki.fi
X-Mailman-Version: 3.3.9rc6
Reply-To: last-call@ietf.org
List-Id: "IETF announcement list. No discussions." <ietf-announce.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-announce/bvu594stSgYbSv1PsH0wY50iqNM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-announce>
List-Help: <mailto:ietf-announce-request@ietf.org?subject=help>
List-Owner: <mailto:ietf-announce-owner@ietf.org>
List-Post: <mailto:ietf-announce@ietf.org>
List-Subscribe: <mailto:ietf-announce-join@ietf.org>
List-Unsubscribe: <mailto:ietf-announce-leave@ietf.org>

The IESG has received a request from the IP Security Maintenance and
Extensions WG (ipsecme) to consider the following document: - 'Signature
Authentication in the Internet Key Exchange Version 2
   (IKEv2) using PQC'
  <draft-ietf-ipsecme-ikev2-pqc-auth-09.txt> as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits final
comments on this action. Please send substantive comments to the
last-call@ietf.org mailing lists by 2026-07-31. Exceptionally, comments may
be sent to iesg@ietf.org instead. In either case, please retain the beginning
of the Subject line to allow automated sorting.

Abstract


   Signature-based authentication methods are utilized in the Internet
   Key Exchange Version 2 (IKEv2).  The current version of the IKEv2
   protocol, specified in RFC 7296, supports traditional digital
   signatures.

   This document specifies a generic mechanism for integrating post-
   quantum cryptographic (PQC) digital signature algorithms into the
   IKEv2 protocol.  The approach allows for seamless inclusion of any
   PQC signature scheme within the existing authentication framework of
   IKEv2.  Additionally, it outlines how Module-Lattice-Based Digital
   Signatures (ML-DSA) and Stateless Hash-Based Digital Signatures (SLH-
   DSA), can be employed as authentication methods within the IKEv2
   protocol, as they have been standardized by US NIST.




The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-pqc-auth/



No IPR declarations have been submitted directly on this I-D.