[IPsec] Public comment period for: Guide to IPsec VPNs: NIST Releases Draft of SP 800-77 Rev. 1

Paul Wouters <paul@nohats.ca> Fri, 12 July 2019 03:13 UTC

Return-Path: <paul@nohats.ca>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DBEFB120052 for <ipsec@ietfa.amsl.com>; Thu, 11 Jul 2019 20:13:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nohats.ca
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1hdGh4KHHkFL for <ipsec@ietfa.amsl.com>; Thu, 11 Jul 2019 20:13:08 -0700 (PDT)
Received: from mx.nohats.ca (mx.nohats.ca [193.110.157.68]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1472E12001E for <ipsec@ietf.org>; Thu, 11 Jul 2019 20:13:08 -0700 (PDT)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 45lJ012bQ3z6S for <ipsec@ietf.org>; Fri, 12 Jul 2019 05:13:05 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1562901185; bh=NhFsnZ7RiqvtoRFmkVvb80oEcYhShlD037XQe1Gtc9I=; h=Date:From:To:Subject; b=nGcx7JrVS8cv9jeAbPJKHl1yJZl5Mpckj7gwPkMVptZ0U31OgI9ujlNY3N0jdT5HK MepxDz7TZf3bAjX9ycory4GX2ac1y1FAEnoOFkLFClLZ0HkPp1Nmr1dej/0h223j3V xKvwGmZObf1YJH3Lkjqk3ut0uTY7qsb8Q23+zz/k=
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id qdxsB-ncBFGP for <ipsec@ietf.org>; Fri, 12 Jul 2019 05:13:03 +0200 (CEST)
Received: from bofh.nohats.ca (bofh.nohats.ca [76.10.157.69]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS for <ipsec@ietf.org>; Fri, 12 Jul 2019 05:13:02 +0200 (CEST)
Received: by bofh.nohats.ca (Postfix, from userid 1000) id 992AF4AA; Thu, 11 Jul 2019 23:13:01 -0400 (EDT)
DKIM-Filter: OpenDKIM Filter v2.11.0 bofh.nohats.ca 992AF4AA
Received: from localhost (localhost [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id 8CB5841064B9 for <ipsec@ietf.org>; Thu, 11 Jul 2019 23:13:01 -0400 (EDT)
Date: Thu, 11 Jul 2019 23:13:01 -0400
From: Paul Wouters <paul@nohats.ca>
To: "ipsec@ietf.org WG" <ipsec@ietf.org>
Message-ID: <alpine.LRH.2.21.1907112311230.9858@bofh.nohats.ca>
User-Agent: Alpine 2.21 (LRH 202 2017-01-01)
MIME-Version: 1.0
Content-Type: text/plain; CHARSET="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/qsVUIGTbwwmXoXtskSjdSA8OWvM>
Subject: [IPsec] Public comment period for: Guide to IPsec VPNs: NIST Releases Draft of SP 800-77 Rev. 1
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Jul 2019 03:13:10 -0000

FYI,

From: NIST Computer Security Division <csrc.nist@service.govdelivery.com>
Subject: Guide to IPsec VPNs: NIST Releases Draft of SP 800-77 Rev. 1
Date: Tuesday, July 2, 2019 at 3:32 PM


NIST invites comments on Draft Special Publication (SP) 800-77 Revision 1, Guide to IPsec VPNs, which contains practical recommendations for
implementing security services based on IPsec and IKE to assist organizations in mitigating the risks associated with transmitting sensitive
information across networks. Since the original publication of SP 800-77 in 2005, IPsec and IKE protocols have been enhanced, and much
operational experience has been gained from the security solutions deployed. This revision contains new security and cryptographic
recommendations and requirements with a focus on how IPsec provides network layer security services. The document also describes how
organizations can implement IPsec, IKE, and their alternatives under varying circumstances.

A public comment period for this document is open until October 8, 2019. See the publication details for a copy of the document and
instructions for submitting comments.

Publication details:|
https://csrc.nist.gov/publications/detail/sp/800-77/rev-1/draft

CSRC update:
https://csrc.nist.gov/news/2019/nist-releases-draft-sp-800-77-rev-1-for-comment 

Paul