--- 1/draft-kivinen-ipsecme-signature-auth-03.txt 2013-12-09 14:51:00.754943733 -0800 +++ 2/draft-kivinen-ipsecme-signature-auth-04.txt 2013-12-09 14:51:00.786944665 -0800 @@ -1,20 +1,20 @@ IP Security Maintenance and Extensions T. Kivinen (ipsecme) INSIDE Secure -Internet-Draft November 14, 2013 +Internet-Draft December 9, 2013 Updates: RFC 5996 (if approved) Intended status: Standards Track -Expires: May 18, 2014 +Expires: June 12, 2014 Signature Authentication in IKEv2 - draft-kivinen-ipsecme-signature-auth-03.txt + draft-kivinen-ipsecme-signature-auth-04.txt Abstract The Internet Key Exchange Version 2 (IKEv2) protocol has limited support for the Elliptic Curve Digital Signature Algorithm (ECDSA). The current version only includes support for three Elliptic Curve groups, and there is fixed hash algorithm tied to each curve. This document generalizes the IKEv2 signature support so it can support any signature method supported by the PKIX and also adds signature hash algorithm negotiation. This is generic mechanism, and is not @@ -29,21 +29,21 @@ Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at http://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." - This Internet-Draft will expire on May 18, 2014. + This Internet-Draft will expire on June 12, 2014. Copyright Notice Copyright (c) 2013 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (http://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents @@ -369,21 +369,23 @@ SHA2-384 3 SHA2-512 4 MD5 is not included to the hash algorithm list as it is not considered safe enough for signature hash uses. Values 5-1023 are reserved to IANA. Values 1024-65535 are for private use among mutually consenting parties. This specification also allocates one new IKEv2 Notify Message Types - - Status Types value for the SIGNATURE_HASH_ALGORITHMS. + - Status Types value for the SIGNATURE_HASH_ALGORITHMS, and adds new + value "Digital Signature" to the IKEv2 Authentication Method + registry. 8. Acknowledgements Most of this work was based on the work done in the IPsecME design team for the ECDSA. The design team members were: Dan Harking, Johannes Merkle, Tero Kivinen, David McGrew, and Yoav Nir. 9. References 9.1. Normative References