Re: Crypto algorithms for IKEv2

Paul Hoffman / VPNC <paul.hoffman@vpnc.org> Thu, 15 May 2003 01:48 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA12346 for <ipsec-archive@lists.ietf.org>; Wed, 14 May 2003 21:48:30 -0400 (EDT)
Received: by lists.tislabs.com (8.9.1/8.9.1) id TAA13210 Wed, 14 May 2003 19:37:08 -0400 (EDT)
Mime-Version: 1.0
X-Sender: phoffvpnc@mail.vpnc.org
Message-Id: <p05210613bae882fae1b0@[63.202.92.152]>
In-Reply-To: <p0521060cbad316b2792a@[63.202.92.152]>
References: <p0521060cbad316b2792a@[63.202.92.152]>
X-Habeas-SWE-1: winter into spring
X-Habeas-SWE-2: brightly anticipated
X-Habeas-SWE-3: like Habeas SWE (tm)
X-Habeas-SWE-4: Copyright 2002 Habeas (tm)
X-Habeas-SWE-5: Sender Warranted Email (SWE) (tm). The sender of this
X-Habeas-SWE-6: email in exchange for a license for this Habeas
X-Habeas-SWE-7: warrant mark warrants that this is a Habeas Compliant
X-Habeas-SWE-8: Message (HCM) and not spam. Please report use of this
X-Habeas-SWE-9: mark in spam to <http://www.habeas.com/report>.
Date: Wed, 14 May 2003 16:42:23 -0700
To: ipsec@lists.tislabs.com
From: Paul Hoffman / VPNC <paul.hoffman@vpnc.org>
Subject: Re: Crypto algorithms for IKEv2
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

Greetings again. Based on the feedback from the WG, I have revised my 
crypto algorithms for IKEv2 draft. The new version is available at 
<ftp://ftp.ietf.org/internet-drafts/draft-hoffman-ipsec-algorithms-01.txt>.

The changes are:

2.1: Removed ENCR_DES_IV32 and ENCR_RC4, which didn't have references,
and renumbered the ones below them. Also added draft names for AES
ciphers.

2.2: Added a reference for PRF_AES128_CBC, but am not sure this is
correct or sufficient.

2.3: Removed DES_MAC because there was no reference for it. Renumbered.
Added reference for AUTH_AES_XCBC_96.

3.1 and 3.2: Added requirements for perfect forward secrecy.

3.2: Updated the IDs because of the renumbering in sections 2.1 and 2.3.

Please review the document and post any comments to the WG mailing 
list. It would be good to get this part of the IKEv2 work finished 
soon.

--Paul Hoffman, Director
--VPN Consortium