[IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-downgrade-prevention-01 (Ends 2026-03-02)
"Kampanakis, Panos" <kpanos@amazon.com> Fri, 27 February 2026 16:01 UTC
Return-Path: <prvs=511cb7732=kpanos@amazon.com>
X-Original-To: ipsec@mail2.ietf.org
Delivered-To: ipsec@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 99094BFB89A5; Fri, 27 Feb 2026 08:01:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.093
X-Spam-Level:
X-Spam-Status: No, score=-2.093 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=amazon.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B1NGpVpapTTl; Fri, 27 Feb 2026 08:01:33 -0800 (PST)
Received: from pdx-out-003.esa.us-west-2.outbound.mail-perimeter.amazon.com (pdx-out-003.esa.us-west-2.outbound.mail-perimeter.amazon.com [44.246.68.102]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 9DE3FBFB898E; Fri, 27 Feb 2026 08:01:32 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.com; i=@amazon.com; q=dns/txt; s=amazoncorp2; t=1772208092; x=1803744092; h=from:to:cc:date:message-id:references:in-reply-to: mime-version:subject; bh=gmIMX749PgYKLkZjrePHl7v5oKyISkT3PIAVmh2xtOA=; b=C43BzX+qOQzBd+UueZvMwF9drkdlGG0VvF+o+WZCnqT3TgaRqnv40YQ5 doq2yMS55SB11SVDkaLZarVUe6VbTlbQw8cihyXpOiV3h7yTwRNh4nRFg 4Wj95/h4UOkfT5yRgftJvAV0ksWhACJPcujvuHN2qM7KE+6poQqtwgrQP Z9qBwwyZ5XMDE1tTh4LU3NdGBPRd/026R0creQ7Z6S+blGvdCH3swa4SS x6gUVj9Bkq0kFFz+ce6tlvxegXnngQJEcanvuFBKVkJoq9ToeYDT7FQBR pne769riarNriVK2A43AbDBZmy71tMZDqSuFthQTHv5qs7F7nG3jF4EIO w==;
X-CSE-ConnectionGUID: Qce6UjOHSNedt899HXayEA==
X-CSE-MsgGUID: YZtgg1/MRT2WVRC9yDJHcw==
X-IronPort-AV: E=Sophos;i="6.21,314,1763424000"; d="scan'208,217";a="13961863"
Thread-Topic: [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-downgrade-prevention-01 (Ends 2026-03-02)
Received: from ip-10-5-0-115.us-west-2.compute.internal (HELO smtpout.naws.us-west-2.prod.farcaster.email.amazon.dev) ([10.5.0.115]) by internal-pdx-out-003.esa.us-west-2.outbound.mail-perimeter.amazon.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 27 Feb 2026 16:01:22 +0000
Received: from EX19MTAUWA002.ant.amazon.com [205.251.233.234:3822] by smtpin.naws.us-west-2.prod.farcaster.email.amazon.dev [10.0.61.162:2525] with esmtp (Farcaster) id 5658f678-1eb3-4665-93e1-d47d2541ebb9; Fri, 27 Feb 2026 16:01:22 +0000 (UTC)
X-Farcaster-Flow-ID: 5658f678-1eb3-4665-93e1-d47d2541ebb9
Received: from EX19EXOUWC002.ant.amazon.com (10.250.64.172) by EX19MTAUWA002.ant.amazon.com (10.250.64.202) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.37; Fri, 27 Feb 2026 16:01:21 +0000
Received: from SJ0PR08CU001.outbound.protection.outlook.com (10.250.64.238) by EX19EXOUWC002.ant.amazon.com (10.250.64.172) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.37 via Frontend Transport; Fri, 27 Feb 2026 16:01:21 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=HpIunDq/urT0zJU0mTAwwcWkg+KRjkEq62st+fx6VmWyM8E6biGHQ0cXClMnUL8Lgvqk8GEdIx3BcOuxCtL+9oUkhtPVNUDmQ4/As/Zc3TH4j3KzZOLSQ6SZuwv7IwRBd54Wsgc65zEhUDe3u5xDIIs4wOHzmPfzGfK/Mb9oIdLV61t55z7JK0dUHfZl+IDdH0ctEZiLOzBw0zOk3S1QI1qf+WNv6jQM27SjMQUBKZEAuzAN5byhr2eiWAL+AVc7sFfxYRtYU8amGJFjBlGAEYJNhj1y1XEtUB6NmLu2bnvlP0uSYnLdcmou6dV9EBFOjcz8l2EsLT2HNfvRapnJNA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gmIMX749PgYKLkZjrePHl7v5oKyISkT3PIAVmh2xtOA=; b=v6WN6JtHL6XX11Zsx301gL1o1XxILTTKhn0tOc02fU+/7CwiAkWgCNRdEIiZwD4Ym9B3I3RRp+ruNGVOs4w9KVJAQyQ7w57BKuxR3HrC6d4zeK7pJGGyCvGQnlxYd2Ydi70yfKl+abPz0mLVr0XKvnGKi4e/iBnT3UG6WNpB+joFxTWKh1mCENuh3oz7wl+l3lTprSiteEOdn51yZpDAwEmiMwvIZwgf5L5qdiPA9019gbePvdqStYUB2bMLLF3a5Ym2gKNm1WOZ3IEqkpEdsFs+9fHbarwZ+1BTG1v2r47uIgIhr3UwHYpJ6q6bdMvys1ncg4lB5QVXhkCpFHqqpA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amazon.com; dmarc=pass action=none header.from=amazon.com; dkim=pass header.d=amazon.com; arc=none
Received: from BYAPR18MB2648.namprd18.prod.outlook.com (2603:10b6:a03:13b::19) by LV1PR18MB6425.namprd18.prod.outlook.com (2603:10b6:408:2b4::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9654.14; Fri, 27 Feb 2026 16:01:17 +0000
Received: from BYAPR18MB2648.namprd18.prod.outlook.com ([fe80::3f0e:882d:13a5:ecd7]) by BYAPR18MB2648.namprd18.prod.outlook.com ([fe80::3f0e:882d:13a5:ecd7%4]) with mapi id 15.20.9654.007; Fri, 27 Feb 2026 16:01:17 +0000
From: "Kampanakis, Panos" <kpanos@amazon.com>
To: Christopher Patton <cpatton=40cloudflare.com@dmarc.ietf.org>, Tero Kivinen <kivinen@iki.fi>
Thread-Index: AQHcp1GgrZ2IW54oX06xArMP0QKOlLWWrsCA
Date: Fri, 27 Feb 2026 16:01:17 +0000
Message-ID: <BYAPR18MB26480BF390878157E1BB5DB1AB73A@BYAPR18MB2648.namprd18.prod.outlook.com>
References: <177126418184.835018.15088804259568141586@dt-datatracker-6ff7c68975-7k42g> <CAG2Zi226T_BKwnv6d+sgfoVPMPyrDvAr-+FjXS9bmOGM72DpWg@mail.gmail.com>
In-Reply-To: <CAG2Zi226T_BKwnv6d+sgfoVPMPyrDvAr-+FjXS9bmOGM72DpWg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=amazon.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BYAPR18MB2648:EE_|LV1PR18MB6425:EE_
x-ms-office365-filtering-correlation-id: d4247cf0-0276-46c9-3958-08de76197127
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|366016|4022899009|1800799024|13003099007|38070700021|8096899003|7053199007;
x-microsoft-antispam-message-info: HZS1U7qDFMQGTdR/06uQXDBS18TZC+fbK7c26cNgAkB/GMXoEhVEGfjGuMRp4WhvC+NY4AZZwuI/SxnZ9s7sNXTDDRIzXz0ksa2tDJpY3lTVLyyiXkiCG/dI0URUCJhKhCXbjkwpPM++oS/dm8/suPSaDZI7P2JDnwKLKLce8aaw25yUN1dy4+nUUt3T+OmwUOIbQp3+pzDyITCD69DndB4N7Hli7kAGtAQkdMGEaIpv5fUfQsrHMAzFdF0XN7oVINZtlHOzalPZKhofMY4CFoOWI8uXEJL+/qNB60Gc5f2pQvCy3WBbcamlDYkAf8C3cnJCHbg8fZHcIpVXaY2vD6rUbEpyRwTlkYSKgEb5sX0iKih9rtjojXClNXzfPt15Q23ibnkSJGigPm2i9+wBI/XeLkZ4CquSiATMexMxzQ/ZsWfNyIUbIzRrJOcFVDhvpBFIhlWPG/jAli1iuIxkjv63gbcLo/FTpgP4cFoJ4kiMBJXIIlsx8KRqhoTswlDSlXK0QDyyCS3rZFGOvnoF01VqgPO5s3qkYp4IRgS78/paS9sZnlgGARgt5g445O46S3XKgOlH35BX81NMiUjNnutU+VZGOjOv1/RhXhsbEG2ptk5tzBcauhJtA2oJJvNBdZMvW4O8Nyb15h6ix8KLMLvl8DeV91Yia/kHnuJTKDpbKq+pLLV3tGNX8kLXjuMiNi02o94wifPjgpX/2uxy4JbTYtULuqL2HcUoSGghNxzVSjcvQOFyCQKhm3UjJF8Q
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:BYAPR18MB2648.namprd18.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(366016)(4022899009)(1800799024)(13003099007)(38070700021)(8096899003)(7053199007);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: atJSxWGe6t3V5r6Hjo5b7szY3FwruCKhLUsIcJNN8fuM2Ubf98e/a5Ep56KNa91n3Ue9DiKU0+OjcYInhbbJY7qjvw/o1EaONTtEI8j2RIIcLnbYaein0mB3hQGQ7Jb/ZNaRzg6Z2NlBc3fyxG0joUfvlStggpbdK5B6EcOw7mAXVbUKfegqIZypMf9NEmxENbLcRDlMy6mtNLP0F4HwQ3bQ1M5mCCJz2oGMp2gEJI6CtlP88ST+QtuynkvLAAPJpVAqQwQJeaCWoDRQ/pB4u1iO5IGqo1PjEv0rDkDQCu2C5SV6jw6c0FrRUTLqMyAp+Sk/yIJO9cWGMsppMO5X0exYRMkwkA/qBwzxSSPm4c364wV0tsfH0l8h93Z7ueiIX3LBftdwW9/UXZIyNSnXnuVtfHOIACUnIlgsCIxHT8GaamAGSdqAMaZD5xqvGpX0irqOpIfu9qErwkuZM+ECriQzPIilXRUZzhC60/u0xudolcgtiB+KKkwjfJCutD0VCQsqA97z0t8b8StLftuIxs+fBd+BxFajNY1OwVdM89iXAi2DkGsj68+uu7y3e3amvVYOuYXBXr0YeWM+6bfuMwq7IJjL8ugIiXuufYLe49YVQO/iVhDwm3JIB+mGoPqp2wVP4xRzipWzCFWwqWQ757dKCRaWnHdV6vuvOgNsZ2sMhB8vGBNRkTNW9OrFGXXBFs3h8PjNP5K0ldS8d5elhVr25pyeBFfJ0m0UP7znN6kb+52YAfRPZ09aqH51llg29AUtgoKrbnNdXR+TmelP9vQBj3la88nvElna5lCZoAr3+/PiQfGBvODJ8fWx8m3HjErqoM716clicUO74Q+IYb4oWnAtIKBdy9fwuM1oGUD0ZuTYYWx4da8EkeHzQD9UQo1cne6q1PkefwEIspbw2AFGyAxEiMUEwrOO7c6DiOoTRwycR9nDSeHjsifT5LtDOTgauh9pcJo2X5FIsx2leRphMy5t9WZ57NN7wVfPl3xFBEeRRWmLJq0RUyUCo5oNjZf7ZshI+M16OwKmQShftgABlN5G3ozpZQnyM3ZF/AGkvQENW5T2/9d8j0jIW6SzGHUt/Y/RJY3YNtRnBzpTHjNZpLbBVYrNYS5ikMwxtLIwIhYqECszeEBp64vr3I6bas9JJfaddj4+bIuZnZ0TijeHVpQg27hXmq8nepx0Qieb0CeSo9oRzlEZzAA+/sxu53tv97gsuKo25UwCOTTAkZlXxH6QIcKVqiUlb1/mJaNIDzuIUMInkU6u0/hKD5DxKGKSgfST4W6AxAzl14Rlycr5BMKVsOzVM+yswJG+wQmLZWRSBIZSP29epsL3MknjN01U1IaMs7KKtY7GNaK3EhD0cYIg3f+4B77mwfEvqYWLat5fvW8ck7dZoT2QiNwWXh+KixD5wxYc8SCPaTVse9OTgDzgAjCn+JbV0MTHEG7fe9CIkWA7o67Bx0tRWoEVVRF28yVCA32pzBG1XreDKJE7Do+3cc5Ao1Gf0AlVZGdU9qyq6hWbDrwGWygdyqHjxjPVddp3VIiGmYdBcxwBWnjEvfD9yfVaeiwVbjdg/rsPXgEIChq6Wldg+jiNREcT2pICEmTYqTAZyYhmz+9vWfqq2g5YhUOYc3quPROjXPnxUesobgTDmGSUH+dTNeU7EJqnitQO7OD1b9rmKGUa9xmsDywvais7DfoNhZe1cYMBTE8DOmToFuzT9b28ROj1
Content-Type: multipart/alternative; boundary="_000_BYAPR18MB26480BF390878157E1BB5DB1AB73ABYAPR18MB2648namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BYAPR18MB2648.namprd18.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: d4247cf0-0276-46c9-3958-08de76197127
X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Feb 2026 16:01:17.7435 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5280104a-472d-4538-9ccf-1e1d0efe8b1b
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: HssZAJleP4Og3SCUmckpgiYCIHkF/Vc/+wVTu/PDsB6LGm8BAR2cK5QqJ9sqU2Rd1/TNbUnXKWP+3pkYScFAUw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: LV1PR18MB6425
X-OriginatorOrg: amazon.com
Message-ID-Hash: BOCDYJQMQZOVUSWQM75T6FQ3ZATYLRPX
X-Message-ID-Hash: BOCDYJQMQZOVUSWQM75T6FQ3ZATYLRPX
X-MailFrom: prvs=511cb7732=kpanos@amazon.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ipsec.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "draft-ietf-ipsecme-ikev2-downgrade-prevention@ietf.org" <draft-ietf-ipsecme-ikev2-downgrade-prevention@ietf.org>, "ipsec@ietf.org" <ipsec@ietf.org>, "ipsecme-chairs@ietf.org" <ipsecme-chairs@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-downgrade-prevention-01 (Ends 2026-03-02)
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/oeYmjrdZB2C9K5e-8ui2p20bbC8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Owner: <mailto:ipsec-owner@ietf.org>
List-Post: <mailto:ipsec@ietf.org>
List-Subscribe: <mailto:ipsec-join@ietf.org>
List-Unsubscribe: <mailto:ipsec-leave@ietf.org>
Hi Chris, I think it is ready, but I have some nits/suggestions: - s/ that are not common, but still not unrealistic/ that are not common, but still plausible/ - s/ break authentication algorithm used by one of the peers in real time/ break the authentication algorithm used by one of the peers in real time/ - s/ has a long-term authentication key for the responder./ has the responder’s long-term authentication key./ - s/ authentication key of initiator A./ authentication key of a different initiator, A./ - Last paragraph of section 4. Mention that this attack used to be less relevant when cryptographic algorithms were considered secure or insecure because peers would disable the insecure ones and not negotiate them. But now with any migration where algorithms co-exist and peers do not know if their peer supports the “strong” algorithm, it becomes more relevant. Or something to that effect. You mention it in Security Consideration, but I think it is important to be in the motivation too. - s/ at least one non-compromised authentication key is used by the peers/ at least one peer’s authentication key is not compromised/ - s/ then the protocol runs as defined in [RFC7296<https://www.ietf.org/archive/id/draft-ietf-ipsecme-ikev2-downgrade-prevention-01.html#RFC7296>]./ then the IKEv2 negotiation runs as defined in [RFC7296<https://www.ietf.org/archive/id/draft-ietf-ipsecme-ikev2-downgrade-prevention-01.html#RFC7296>] - s/ in the IKE SA establishing,/ in the IKE SA establishment,/ - For clarity, add a sentence in Section 7 to mention that subsequent messages like CREATE_CHILD_SA IKE_FOLLOW_UP do not apply to the new signed octets because they follow IKE_AUTH. - s/ It is therefore necessary for each of the peers to mandate the use of a pre-shared key (and abort the connection if negotiation fails)./ It is therefore necessary for peers configured to use a pre-shared key with another peer to abort the connection if the peer does not negotiate the USE_PPK extension./ From: Christopher Patton <cpatton=40cloudflare.com@dmarc.ietf.org> Sent: Thursday, February 26, 2026 1:55 PM To: Tero Kivinen <kivinen@iki.fi> Cc: draft-ietf-ipsecme-ikev2-downgrade-prevention@ietf.org; ipsec@ietf.org; ipsecme-chairs@ietf.org Subject: [EXTERNAL] [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-downgrade-prevention-01 (Ends 2026-03-02) CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe. Hi all, I just wanted to add that we implemented this feature in our internal implementation of IKEv2 and have confirmed interop with strongswan's experimental branch: git clone --depth 1 --branch downgrade-prevention https://github.com/strongswan/strongswan.git One thing we noticed is that the draft doesn't explicitly specify how to handle a malformed IKE_SA_INIT_FULL_TRANSCRIPT_AUTH notification (i.e., one that has a non-empty payload, a non-zero Protocol ID, or a non-zero SPI Size [1]). Our responder handles this case by sending an INVALID_SYNTAX error. (We don't implement an initiator.) My understanding is that this behavior is allowed by IKEv2, but other behaviors are allowed as well. If my understanding is correct, then I don't see a need to make the behavior explicit. Apart from that, I have no more changes for the WG to consider and I think this is ready to go. We look forward to getting a codepoint! Best, Chris P. [1] https://www.ietf.org/archive/id/draft-ietf-ipsecme-ikev2-downgrade-prevention-01.html#section-6-1 On Mon, Feb 16, 2026 at 9:49 AM Tero Kivinen via Datatracker <noreply@ietf.org<mailto:noreply@ietf.org>> wrote: This message starts a WG Last Call for: draft-ietf-ipsecme-ikev2-downgrade-prevention-01 This Working Group Last Call ends on 2026-03-02 Abstract: This document describes an extension to the Internet Key Exchange protocol version 2 (IKEv2) that aims to prevent some kinds of downgrade attacks on this protocol by having the peers confirm they have participated in the same conversation. File can be retrieved from: Please review and indicate your support or objection to proceed with the publication of this document by replying to this email keeping ipsec@ietf.org<mailto:ipsec@ietf.org> in copy. Objections should be explained and suggestions to resolve them are highly appreciated. Authors, and WG participants in general, are reminded of the Intellectual Property Rights (IPR) disclosure obligations described in BCP 79 [1]. Appropriate IPR disclosures required for full conformance with the provisions of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any. Sanctions available for application to violators of IETF IPR Policy can be found at [3]. Thank you. [1] https://datatracker.ietf.org/doc/bcp78/ [2] https://datatracker.ietf.org/doc/bcp79/ [3] https://datatracker.ietf.org/doc/rfc6701/ The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-downgrade-prevention/ There is also an HTMLized version available at: https://datatracker.ietf.org/doc/html/draft-ietf-ipsecme-ikev2-downgrade-prevention-01 A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-ietf-ipsecme-ikev2-downgrade-prevention-01 _______________________________________________ IPsec mailing list -- ipsec@ietf.org<mailto:ipsec@ietf.org> To unsubscribe send an email to ipsec-leave@ietf.org<mailto:ipsec-leave@ietf.org>
- [IPsec] WG Last Call: draft-ietf-ipsecme-ikev2-do… Tero Kivinen via Datatracker
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Thom Wiggers
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Christopher Patton
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Bas Westerbaan
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Christopher Patton
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Christopher Patton
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Wang Guilin
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Wang Guilin
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Bas Westerbaan
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Keegan Dasilva Barbosa
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Kampanakis, Panos
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Keegan Dasilva Barbosa
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov
- [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev… Valery Smyslov