[IPsec] Fwd: I-D Action:draft-hoffman-ikev2bis-02.txt

Paul Hoffman <paul.hoffman@vpnc.org> Sat, 17 November 2007 20:02 UTC

Return-path: <ipsec-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1ItTs9-0001VC-9C; Sat, 17 Nov 2007 15:02:33 -0500
Received: from ipsec by megatron.ietf.org with local (Exim 4.43) id 1ItTs7-0001Ut-Nm for ipsec-confirm+ok@megatron.ietf.org; Sat, 17 Nov 2007 15:02:31 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1ItTs7-0001Ug-E1 for ipsec@ietf.org; Sat, 17 Nov 2007 15:02:31 -0500
Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1ItTs3-0001rE-2r for ipsec@ietf.org; Sat, 17 Nov 2007 15:02:31 -0500
Received: from [165.227.249.203] (dsl-63-249-108-169.cruzio.com [63.249.108.169]) (authenticated bits=0) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id lAHK2Oc7023062 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <ipsec@ietf.org>; Sat, 17 Nov 2007 13:02:26 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
Mime-Version: 1.0
Message-Id: <p0624080cc364f8d726b4@[165.227.249.203]>
Date: Sat, 17 Nov 2007 12:02:08 -0800
To: IPsec WG <ipsec@ietf.org>
From: Paul Hoffman <paul.hoffman@vpnc.org>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 92df29fa99cf13e554b84c8374345c17
Subject: [IPsec] Fwd: I-D Action:draft-hoffman-ikev2bis-02.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Errors-To: ipsec-bounces@ietf.org

>A New Internet-Draft is available from the on-line Internet-Drafts 
>directories.
>
>	Title           : Internet Key Exchange Protocol: IKEv2
>	Author(s)       : C. Kaufman, et al.
>	Filename        : draft-hoffman-ikev2bis-02.txt
>	Pages           : 125
>	Date            : 2007-11-17
>
>This document describes version 2 of the Internet Key Exchange (IKE)
>protocol.  It is a restatement of RFC 4306, and includes all of the
>clarifications from RFC 4718.
>
>A URL for this Internet-Draft is:
>http://www.ietf.org/internet-drafts/draft-hoffman-ikev2bis-02.txt

Almost all of the changes came from Pasi (thanks, Pasi!). The change 
list from the document is:

    Many grammatical fixes.

    In Section 1.2, reworded Clarif-4.3 to be clearer.

    In Section 1.3.3, reworded 3.10.1-16393 and Clarif-5.4 to remove
    redundant text.

    In Section 2.13, replaced text about variable length keys with
    clearer explanation and requirement on non-HMAC PRFs.  Also added
    "preferred" to Section 2.14 for the key length, and removed redundant
    text.

    In Section 2.14, removed the "half and half" description and replaced
    it with exceptions for RFC4434 and RFC4615.

    Removed the now-redundant "All PRFs used with IKEv2 MUST take
    variable-sized keys" from Section 2.15.

    In Section 2.15, added "(IKE_SA_INIT response)" after "of the second
    message" and "(IKE_SA_INIT request)" after "the first message".

    In Section 2.17, simplified because there are no more bundles.  "A
    single CHILD_SA negotiation may result in multiple security
    associations.  ESP and AH SAs exist in pairs (one in each
    direction)." becomes "For ESP and AH, a single CHILD_SA negotiation
    results in two security associations (one in each direction)."

    In section 3.3, made the example of combinations of algorithms and
    the contents of the first proposal clearer.

    Added Clarif-4.4 to the ned of Section 3.3.2.

    Reordered Section 3.3.5 and added Clarif-7.11.

    Clarified Section 3.3.6 about choosing a single proposal.  Also added
    second paragraph about transforms not understood, and clarified third
    paragraph about picking D-H groups.

    Moved 3.10.1-16392 from Section 3.6 to 3.7.

    In Section 3.10, clarified 3.10.1-16394.

    Updated Section 6 to indicate that there is nothing new for IANA in
    this spec.  Also removed the definition of "Expert Review" from
    Section 1.6 for the same reason.

    In Appendix A, removed "and not commit any state to an exchange until
    the initiator can be cryptographically authenticated" because that
    was only true in an earlier version of IKEv2.

--Paul Hoffman, Director
--VPN Consortium


_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec