[IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-downgrade-prevention-01 (Ends 2026-03-02)
Wang Guilin <Wang.Guilin@huawei.com> Mon, 02 March 2026 02:41 UTC
Return-Path: <Wang.Guilin@huawei.com>
X-Original-To: ipsec@mail2.ietf.org
Delivered-To: ipsec@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E402BC1583DE; Sun, 1 Mar 2026 18:41:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.196
X-Spam-Level:
X-Spam-Status: No, score=-4.196 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xljdhynTsT1Z; Sun, 1 Mar 2026 18:41:58 -0800 (PST)
Received: from frasgout.his.huawei.com (frasgout.his.huawei.com [185.176.79.56]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 3E706C1583D7; Sun, 1 Mar 2026 18:41:58 -0800 (PST)
Received: from mail.maildlp.com (unknown [172.18.224.150]) by frasgout.his.huawei.com (SkyGuard) with ESMTPS id 4fPNTt2xxrzHnGgf; Mon, 2 Mar 2026 10:41:06 +0800 (CST)
Received: from kwepemh500011.china.huawei.com (unknown [7.202.181.142]) by mail.maildlp.com (Postfix) with ESMTPS id 2FD8F4056A; Mon, 2 Mar 2026 10:41:57 +0800 (CST)
Received: from sinpeml500007.china.huawei.com (7.188.194.98) by kwepemh500011.china.huawei.com (7.202.181.142) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Mon, 2 Mar 2026 10:41:22 +0800
Received: from sinpeml500009.china.huawei.com (7.188.194.209) by sinpeml500007.china.huawei.com (7.188.194.98) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Mon, 2 Mar 2026 10:41:21 +0800
Received: from sinpeml500009.china.huawei.com ([7.188.194.209]) by sinpeml500009.china.huawei.com ([7.188.194.209]) with mapi id 15.02.1544.011; Mon, 2 Mar 2026 10:41:21 +0800
From: Wang Guilin <Wang.Guilin@huawei.com>
To: Tero Kivinen <kivinen@iki.fi>, "draft-ietf-ipsecme-ikev2-downgrade-prevention@ietf.org" <draft-ietf-ipsecme-ikev2-downgrade-prevention@ietf.org>, "ipsec@ietf.org" <ipsec@ietf.org>, "ipsecme-chairs@ietf.org" <ipsecme-chairs@ietf.org>
Thread-Topic: [IPsec] WG Last Call: draft-ietf-ipsecme-ikev2-downgrade-prevention-01 (Ends 2026-03-02)
Thread-Index: AQHcn2y3AQFPmptqx066yVRoqirQzLWalimg
Date: Mon, 02 Mar 2026 02:41:21 +0000
Message-ID: <862fcf83b8e645e98662056a8d8c4d79@huawei.com>
References: <177126418184.835018.15088804259568141586@dt-datatracker-6ff7c68975-7k42g>
In-Reply-To: <177126418184.835018.15088804259568141586@dt-datatracker-6ff7c68975-7k42g>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.194.120.91]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Message-ID-Hash: ST6LARQGOICZZDXAGWYJMRS2GDED4VIG
X-Message-ID-Hash: ST6LARQGOICZZDXAGWYJMRS2GDED4VIG
X-MailFrom: Wang.Guilin@huawei.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ipsec.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Wang Guilin <Wang.Guilin@huawei.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-downgrade-prevention-01 (Ends 2026-03-02)
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/SUEIPJ8gFgZq3_6RG5L0U4Ld1l4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Owner: <mailto:ipsec-owner@ietf.org>
List-Post: <mailto:ipsec@ietf.org>
List-Subscribe: <mailto:ipsec-join@ietf.org>
List-Unsubscribe: <mailto:ipsec-leave@ietf.org>
I support the publication of this document. The update by itself is important, and also the downgrade attacks demonstrated are good examples for security research and standardization practice. Below is my review with some technical and editorial comments. Hope they are useful to improve the readability of the specification. Cheers, Guilin ============= Technical Comments Section 3. In the end of this part, it may be good to point out whey the current formation of AUTH_Data in IKEv2 it not really secure, so the attacks in Section 4 is possible. In this way, the two sections are linked more tightly. Here is some text for reference: "Here, the Initiator also authenticates the None from the responder to prevent replay attack, a common practice in authentication. But, this is unfortunately still not enough, as the downgrade attacks shown in Section 5." Section 4. a) One or two diagrams for both attacks described in Section 4? The current description is clear and easy to follow for guys familiar with IKEv2 [RFC 7296], but may be not easy for the readers who are not such familiar with IKEv2. If one or two diagrams given, it will help those readers, I think. b) Precondition 1: "The attacker must be on the path" also means the attacker is on live? To mount the attacks, this is necessary, I think. c) When talking to attack 2, "In this case the attacker cannot change the algorithms selected by the responder, ...". This sentence seems not really accurate, as the main attack described above is actually not about changing the algorithms selected by the responder, but changing the pool of the algorithms from which the responder can select an algorithm. d) It may be helpful to mention that attacker 2 is applicable for an insider attacker A, who is an legitimate user just like R (e.g, R's colleagues), but A is trying to mount attack 2 targeting I and R as the victims. ----------------------------- Editorial Comments Section 4. a) "the attack can be mount as follows" => "the attack can be mounted as follows" b) "must include public key for a "weak" key exchange method. " => "must include one public key for a "weak" key exchange method. " c) "Instead, the attacker only needs to know the long-term authentication key of some party one of the peers is configured to communicate with. " => "Instead, the attacker only needs to know the long-term authentication key of some party with whom one of the peers is configured to communicate. " d) " if at least one non-compromised authentication key is used by the peers in the protocol run" => " if at least one key used by the peers is not compromised in the protocol run" ?? Section 7.1: "Note, that authentication of the IKE_INTERMEDIATE exchange includes ..." => "Note that authentication of the IKE_INTERMEDIATE exchange includes ..." or "Note: authentication of the IKE_INTERMEDIATE exchange includes ..." ================ -----Original Message----- From: Tero Kivinen via Datatracker <noreply@ietf.org> Sent: Tuesday, 17 February 2026 1:50 am To: draft-ietf-ipsecme-ikev2-downgrade-prevention@ietf.org; ipsec@ietf.org; ipsecme-chairs@ietf.org Subject: [IPsec] WG Last Call: draft-ietf-ipsecme-ikev2-downgrade-prevention-01 (Ends 2026-03-02) This message starts a WG Last Call for: draft-ietf-ipsecme-ikev2-downgrade-prevention-01 This Working Group Last Call ends on 2026-03-02 Abstract: This document describes an extension to the Internet Key Exchange protocol version 2 (IKEv2) that aims to prevent some kinds of downgrade attacks on this protocol by having the peers confirm they have participated in the same conversation. File can be retrieved from: Please review and indicate your support or objection to proceed with the publication of this document by replying to this email keeping ipsec@ietf.org in copy. Objections should be explained and suggestions to resolve them are highly appreciated. Authors, and WG participants in general, are reminded of the Intellectual Property Rights (IPR) disclosure obligations described in BCP 79 [1]. Appropriate IPR disclosures required for full conformance with the provisions of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any. Sanctions available for application to violators of IETF IPR Policy can be found at [3]. Thank you. [1] https://datatracker.ietf.org/doc/bcp78/ [2] https://datatracker.ietf.org/doc/bcp79/ [3] https://datatracker.ietf.org/doc/rfc6701/ The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-downgrade-prevention/ There is also an HTMLized version available at: https://datatracker.ietf.org/doc/html/draft-ietf-ipsecme-ikev2-downgrade-prevention-01 A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-ietf-ipsecme-ikev2-downgrade-prevention-01 _______________________________________________ IPsec mailing list -- ipsec@ietf.org To unsubscribe send an email to ipsec-leave@ietf.org
- [IPsec] WG Last Call: draft-ietf-ipsecme-ikev2-do… Tero Kivinen via Datatracker
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Thom Wiggers
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Christopher Patton
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Bas Westerbaan
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Christopher Patton
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Christopher Patton
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Wang Guilin
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Wang Guilin
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Bas Westerbaan
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Keegan Dasilva Barbosa
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Kampanakis, Panos
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Keegan Dasilva Barbosa
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov