[IPsec] Fwd: I-D Action:draft-hoffman-ikev2bis-02.txt
Paul Hoffman <paul.hoffman@vpnc.org> Sat, 17 November 2007 20:02 UTC
Return-path: <ipsec-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1ItTs9-0001VC-9C; Sat, 17 Nov 2007 15:02:33 -0500
Received: from ipsec by megatron.ietf.org with local (Exim 4.43) id 1ItTs7-0001Ut-Nm for ipsec-confirm+ok@megatron.ietf.org; Sat, 17 Nov 2007 15:02:31 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1ItTs7-0001Ug-E1 for ipsec@ietf.org; Sat, 17 Nov 2007 15:02:31 -0500
Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1ItTs3-0001rE-2r for ipsec@ietf.org; Sat, 17 Nov 2007 15:02:31 -0500
Received: from [165.227.249.203] (dsl-63-249-108-169.cruzio.com [63.249.108.169]) (authenticated bits=0) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id lAHK2Oc7023062 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <ipsec@ietf.org>; Sat, 17 Nov 2007 13:02:26 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
Mime-Version: 1.0
Message-Id: <p0624080cc364f8d726b4@[165.227.249.203]>
Date: Sat, 17 Nov 2007 12:02:08 -0800
To: IPsec WG <ipsec@ietf.org>
From: Paul Hoffman <paul.hoffman@vpnc.org>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 92df29fa99cf13e554b84c8374345c17
Subject: [IPsec] Fwd: I-D Action:draft-hoffman-ikev2bis-02.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
Errors-To: ipsec-bounces@ietf.org
>A New Internet-Draft is available from the on-line Internet-Drafts
>directories.
>
> Title : Internet Key Exchange Protocol: IKEv2
> Author(s) : C. Kaufman, et al.
> Filename : draft-hoffman-ikev2bis-02.txt
> Pages : 125
> Date : 2007-11-17
>
>This document describes version 2 of the Internet Key Exchange (IKE)
>protocol. It is a restatement of RFC 4306, and includes all of the
>clarifications from RFC 4718.
>
>A URL for this Internet-Draft is:
>http://www.ietf.org/internet-drafts/draft-hoffman-ikev2bis-02.txt
Almost all of the changes came from Pasi (thanks, Pasi!). The change
list from the document is:
Many grammatical fixes.
In Section 1.2, reworded Clarif-4.3 to be clearer.
In Section 1.3.3, reworded 3.10.1-16393 and Clarif-5.4 to remove
redundant text.
In Section 2.13, replaced text about variable length keys with
clearer explanation and requirement on non-HMAC PRFs. Also added
"preferred" to Section 2.14 for the key length, and removed redundant
text.
In Section 2.14, removed the "half and half" description and replaced
it with exceptions for RFC4434 and RFC4615.
Removed the now-redundant "All PRFs used with IKEv2 MUST take
variable-sized keys" from Section 2.15.
In Section 2.15, added "(IKE_SA_INIT response)" after "of the second
message" and "(IKE_SA_INIT request)" after "the first message".
In Section 2.17, simplified because there are no more bundles. "A
single CHILD_SA negotiation may result in multiple security
associations. ESP and AH SAs exist in pairs (one in each
direction)." becomes "For ESP and AH, a single CHILD_SA negotiation
results in two security associations (one in each direction)."
In section 3.3, made the example of combinations of algorithms and
the contents of the first proposal clearer.
Added Clarif-4.4 to the ned of Section 3.3.2.
Reordered Section 3.3.5 and added Clarif-7.11.
Clarified Section 3.3.6 about choosing a single proposal. Also added
second paragraph about transforms not understood, and clarified third
paragraph about picking D-H groups.
Moved 3.10.1-16392 from Section 3.6 to 3.7.
In Section 3.10, clarified 3.10.1-16394.
Updated Section 6 to indicate that there is nothing new for IANA in
this spec. Also removed the definition of "Expert Review" from
Section 1.6 for the same reason.
In Appendix A, removed "and not commit any state to an exchange until
the initiator can be cryptographically authenticated" because that
was only true in an earlier version of IKEv2.
--Paul Hoffman, Director
--VPN Consortium
_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec
- [IPsec] Fwd: I-D Action:draft-hoffman-ikev2bis-02… Paul Hoffman
- [IPsec] Re: Fwd: I-D Action:draft-hoffman-ikev2bi… Michael Richardson
- [IPsec] Re: Fwd: I-D Action:draft-hoffman-ikev2bi… Tero Kivinen
- [IPsec] Re: Fwd: I-D Action:draft-hoffman-ikev2bi… Michael Richardson
- RE: [IPsec] Re: Fwd: I-D Action:draft-hoffman-ike… Pasi.Eronen
- [IPsec] Re: Fwd: I-D Action:draft-hoffman-ikev2bi… Michael Richardson
- [IPsec] Re: Fwd: I-D Action:draft-hoffman-ikev2bi… Michael Richardson
- [IPsec] Re: Fwd: I-D Action:draft-hoffman-ikev2bi… Michael Richardson
- RE: [IPsec] Re: Fwd: I-D Action:draft-hoffman-ike… Pasi.Eronen