Implemented Standards: Difference between revisions

From Libreswan
Jump to navigation Jump to search
(update PPK link to RFC; move INTERMEDIATE to IKEv2 section)
(refresh list)
 
(51 intermediate revisions by 3 users not shown)
Line 1: Line 1:


The following table lists the RFCs, drafts and standards related to IKE and IPsec. An overview of IKE and IPsec related RFC's is available in
The following table lists the RFCs, drafts and standards related to IKE and IPsec. An overview of IKE and IPsec related RFC's is available in
[http://tools.ietf.org/html/rfc6071 RFC 6071].
[https://datatracker.ietf.org/doc/html/rfc6071 RFC 6071].


Implementation status can be: implemented (v), planned (p), not implemented (-) or will not be implemented (X)
Implementation status can be: implemented (yes, vX.X), planned (p), not implemented (-), will not be implemented (X) and work in progress (wip)


{|border=1
All the standards, including drafts can be found at [https://datatracker.ietf.org/wg/ipsecme/documents/ IP Security Maintenance and Extensions]
! style="text-align:left;" | Status
 
== [https://datatracker.ietf.org/doc/html/rfc7296 IKEv2 RFC 7296] ==
 
{| class="wikitable"
! style="text-align:left;" | Standard
! style="text-align:left;" | Standard
! style="text-align:left;" | Description
! style="text-align:left;" | Description
! style="text-align:left;" | Status
! style="text-align:left;" | Comments
! style="text-align:left;" | Comments
|-
|-
| colspan="4"| IKEv1
| [https://datatracker.ietf.org/doc/html/rfc9478 RFC 9478]
| Labeled IPsec Traffic Selector support for IKEv2
| v4.4
|
|-
| [https://datatracker.ietf.org/doc/html/rfc9464 RFC 9464]
| Configuration for Encrypted DNS
|
|
|-
| [https://datatracker.ietf.org/doc/html/rfc9370 RFC 9370]
| Intermediate Exchange in the IKEv2 Protocol
|
| aka IKE_INTERMEDIATE + IKE_FOLLOWUP_KE
|-
| [https://datatracker.ietf.org/doc/html/rfc9347 RFC 9347]
| Aggregation and Fragmentation Mode for Encapsulating Security Payload (ESP) and Its Use for IP Traffic Flow Security (IP-TFS)
| p
|  
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc9242 RFC 9242]
| Intermediate Exchange in the IKEv2 Protocol
| v
| v
| [http://tools.ietf.org/html/rfc2407 RFC 2407]
| aka IKE_INTERMEDIATE
| IPsec Domain of Interpretation for ISAKMP (IPsec DoI)
|-
| [https://datatracker.ietf.org/doc/html/rfc8784/ RFC 8784]
| Postquantum Preshared Keys for IKEv2
| v3.25
|  
|  
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc8420 RFC 8420]
| Using the Edwards-Curve Digital Signature Algorithm (EdDSA) in the Internet Key Exchange Protocol Version 2 (IKEv2)
| wip
| Code is available in a branch, but requires NSS patches - waiting on NSS merge before merging into libreswan
|-
| [https://datatracker.ietf.org/doc/html/rfc8247 RFC 8247]
| Algorithm Implementation Requirements and Usage Guidance for the Internet Key Exchange Protocol Version 2 (IKEv2)
| v
| v
| [http://tools.ietf.org/html/rfc2408 RFC 2408]
| Internet Security Association and Key Management Protocol (ISAKMP)
|
|
|-
|-
| v
| [https://datatracker.ietf.org/doc/html/rfc8229 RFC 8229]
| [http://tools.ietf.org/html/rfc2409 RFC 2409]
| TCP Encapsulation of IKE and IPsec Packets
| Internet Key Exchange (IKE)
| v4.0
| Revised Mode not implemented
| IKE over TCP implemented and IKE over ESP supported on Linux 5.6+ kernels. Does not currently support IKE/ESP over TLS
|-
|-
| v
| [https://datatracker.ietf.org/doc/html/rfc8019 RFC 8019]
| [https://tools.ietf.org/html/rfc3526 RFC 3526]
| Protecting Internet Key Exchange Protocol Version 2 (IKEv2) Implementations from Distributed Denial-of-Service Attacks
| More Modular Exponential (MODP) Diffie-Hellman groups
| -
|
|
|-
|-
| v
| [https://datatracker.ietf.org/doc/html/rfc7815 RFC 7815]
| [https://tools.ietf.org/html/rfc3706 RFC 3706]
| Minimal Internet Key Exchange Version 2 (IKEv2) Initiator Implementation
| A Traffic-Based Method of Detecting Dead Internet Key Exchange (IKE) Peers
| '''X'''
| known as "DPD"
| This is a really just a subset of IKEv2 [http://datatracker.ietf.org/doc/html/rfc7296 RFC 7296]
|-
|-
| v
| [https://datatracker.ietf.org/doc/html/rfc7670 RFC 7670]
| [https://tools.ietf.org/html/3947 RFC 3947]
| Generic Raw Public-Key Support for IKEv2
| Negotiation of NAT-Traversal in the IKE
| p
| known as "NATT" or "ESPinUDP"
| raw RSA public keys are supported using the core IKE RFCs
|-
|-
| v
| [https://datatracker.ietf.org/doc/html/rfc7651 RFC 7651]
| [http://tools.ietf.org/html/draft-dukes-ike-mode-cfg draft-dukes-ike-mode-cfg]
| 3GPP IP Multimedia Subsystems (IMS) Option for the Internet Key Exchange Protocol Version 2 (IKEv2)
| The ISAKMP Configuration Method
| -
|
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc7634 RFC 7634]
| ChaCha20, Poly1305, and Their Use in the IKE Protocol and IPsec
| v3.26
|
|-
| [https://datatracker.ietf.org/doc/html/rfc7619 RFC 7619]
| The NULL Authentication Method in the Internet Key Exchange Protocol Version 2 (IKEv2)
| v
| v
| [http://tools.ietf.org/html/draft-ietf-ipsec-isakmp-xauth draft-ietf-ipsec-isakmp-xauth]
| Extended Authentication within ISAKMP/Oakley (XAUTH)
|
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc7427 RFC 7427]
| Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)
| v
| v
| [http://tools.ietf.org/html/draft-jenkins-ipsec-rekeying-06 draft-jenkins-ipsec-rekeying]
| a.k.a. DIGSIG<br>Implementation supports RSS-PSS (v3.26) and ECDSA(v3.26) and RSA-v1.5 (v4.7)
| IPsec Re-keying Issues
| Implementation differs on some point but accomplishes the same
|-
|-
| X
| [https://datatracker.ietf.org/doc/html/rfc7383 RFC 7383]
| [http://tools.ietf.org/html/draft-ietf-ipsec-isakmp-hybrid-auth  draft-ietf-ipsec-isakmp-hybrid-auth]
| Internet Key Exchange Protocol Version 2 (IKEv2) Message Fragmentation
| A Hybrid Authentication Mode for IKE
| v
|
|
|-
|-
| colspan="4"| IKEv2
| [https://datatracker.ietf.org/doc/html/rfc7296 RFC 7296]
|-
| '''Internet Key Exchange Protocol Version 2 (IKEv2)'''
| v
| v
| [http://tools.ietf.org/html/rfc4307 RFC 4307]
| Obsoletes [https://datatracker.ietf.org/doc/html/rfc5996 RFC 5996] and [https://datatracker.ietf.org/doc/html/rfc4718 RFC 4718]
| Cryptographic Algorithms for Use in the Internet Key Exchange Version 2 (IKEv2)
| Obsoleted by [http://tools.ietf.org/html/rfc8247 RFC 8247]
|-
|-
| v
| [https://datatracker.ietf.org/doc/html/rfc6989 RFC 6989]
| [http://tools.ietf.org/html/rfc7296 RFC 7296]
| Additional Diffie-Hellman Tests for the Internet Key Exchange Protocol Version 2 (IKEv2)
| Internet Key Exchange Protocol Version 2 (IKEv2)
| N/A
| Obsoletes [http://tools.ietf.org/html/rfc5996 RFC 5996] and [http://tools.ietf.org/html/rfc4718 RFC 4718]
| This work is or needs to be done inside the nss library
|-
|-
| X
| [https://datatracker.ietf.org/doc/html/rfc6954 RFC 6954]
| [http://tools.ietf.org/html/rfc7815 RFC 7815]
| Using the Elliptic Curve Cryptography (ECC) Brainpool Curves for the Internet Key Exchange Protocol Version 2 (IKEv2)
| Minimal Internet Key Exchange Version 2 (IKEv2) Initiator Implementation
| -
| This is a really just a subset of IKEv2 [http://tools.ietf.org/html/rfc7296 RFC 7296]
|
|-
|-
|p
| [https://datatracker.ietf.org/doc/html/rfc6932 RFC 6932]
| [https://tools.ietf.org/html/rfc4478 RFC 4478]
| Brainpool Elliptic Curves for the IKE Group Description Registry
| Repeated Authentication in Internet Key Exchange (IKEv2) Protocol
| -
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc6867 RFC 6867]
| [https://tools.ietf.org/html/rfc4555 RFC 4555]
| An Internet Key Exchange Protocol Version 2 (IKEv2) Extension to Support EAP Re-authentication Protocol (ERP)
| IKEv2 Mobility and Multihoming Protocol (MOBIKE)
| -
| "Additional Addresses" not supported
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc6631 RFC 6631]
| Password Authenticated Connection Establishment with IKEv2
| -
| -
| [https://tools.ietf.org/html/rfc4595 RFC 4595]
| Use of IKEv2 in the Fibre Channel Security Association Management Protocol
|
|
|-
|-
| p
| [https://datatracker.ietf.org/doc/html/rfc6628 RFC 6628]
| [https://tools.ietf.org/html/rfc4615 RFC 4615]
| Efficient Augmented Password-Only Authentication and Key Exchange for IKEv2
| The AES-Cipher-based Message Authentication Code-Pseudo-Random Function-128 (AES-CMAC-PRF-128) Algorithm for IKE
| -
| CMAC is supoorted as INTEG (for ESP/IKE) but not as PRF(for IKE) - this is pending support in the NSS library.
|-
|N/A
| [https://tools.ietf.org/html/rfc4621 RFC 4621]
| Design of the IKEv2 Mobility and Multihoming (MOBIKE) Protocol
|
|
|-
|-
|p
| [https://datatracker.ietf.org/doc/html/rfc6617 RFC 6617]
| [https://tools.ietf.org/html/rfc4739 RFC 4739]
| Secure Pre-Shared Key (PSK) Authentication for the Internet Key Exchange Protocol (IKE)
| Multiple Authentication Exchanges in the IKEv2 Protocol
| -
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc6467 RFC 6467]
| [https://tools.ietf.org/html/rfc4754 RFC 4754]
| Secure Password Framework for IKEv2
| IKE and IKEv2 Authentication Using the Elliptic Curve Digital Signature Algorithm (ECDSA)
| Added in 3.26
|-
| -
| -
| [https://tools.ietf.org/html/rfc4806 RFC 4806]
|
| Online Certificate Status Protocol (OCSP) Extensions to IKEv2
| Regular OCSP fetching outside of IKE is supported.
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc6311 RFC 6311]
| Protocol Support for High Availability of IKEv2/IPsec
| -
| -
| [https://tools.ietf.org/html/rfc5026 RFC 5026]
| Mobile IPv6 Bootstrapping in Split Scenario
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc6290 RFC 6290]
| [https://tools.ietf.org/html/rfc5282 RFC 5282]
| A Quick Crash Detection Method for the Internet Key Exchange Protocol (IKE)
| Using Authenticated Encryption Algorithms with the Encrypted Payload of the IKEv2 Protocol
| p
| Only AES_GCM is implemented. AES_CCM requires support in the nss library
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc6027 RFC 6027]
| [https://tools.ietf.org/html/rfc5685 RFC 5685]
| IPsec Cluster Problem Statement
| Redirect Mechanism for IKEv2
| N/A
| Added in 3.28
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc6023 RFC 6023]
| A Childless Initiation of the Internet Key Exchange Version 2 (IKEv2) Security Association (SA)
| -
| -
| [https://tools.ietf.org/html/rfc5857 RFC 5857]
| IKEv2 Extensions to Support Robust Header Compression over IPsec
|
|
|-
|-
|p
| [https://datatracker.ietf.org/doc/html/rfc5998 RFC 5998]
| [https://tools.ietf.org/html/rfc5723 RFC 5723]
| An Extension for EAP-only Authentication in IKEv2
| Internet Key Exchange Protocol Version 2 (IKEv2) Session Resumption
| wip
|
|
|-
|-
| -
| [https://datatracker.ietf.org/doc/html/rfc5930 RFC 5930]
| [https://tools.ietf.org/html/rfc5739 RFC 5739]
| Using Advanced Encryption Standard Counter Mode (AES-CTR) with the Internet Key Exchange version 02 (IKEv2) Protocol
| IPv6 Configuration in Internet Key Exchange Protocol Version 2 (IKEv2)
| v
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc5903 RFC 5903]
| [https://tools.ietf.org/html/rfc5903 RFC 5903]
| ECP Groups for IKE and IKEv2
| ECP Groups for IKE and IKEv2
| v
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc5857 RFC 5857]
| [https://tools.ietf.org/html/rfc5930 RFC 5930]
| IKEv2 Extensions to Support Robust Header Compression over IPsec
| Using Advanced Encryption Standard Counter Mode (AES-CTR) with the Internet Key Exchange version 02 (IKEv2) Protocol
| -
|
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc5739 RFC 5739]
| IPv6 Configuration in Internet Key Exchange Protocol Version 2 (IKEv2)
| -
| -
| [https://tools.ietf.org/html/rfc5998 RFC 5998]
| An Extension for EAP-only Authentication in IKEv2
|
|
|-
|-
| -
| [https://datatracker.ietf.org/doc/html/rfc5723 RFC 5723]
| [https://tools.ietf.org/html/rfc6023 RFC 6023]
| Internet Key Exchange Protocol Version 2 (IKEv2) Session Resumption
| A Childless Initiation of the Internet Key Exchange Version 2 (IKEv2) Security Association (SA)
| wip
|
|
|-
|-
| N/A
| [https://datatracker.ietf.org/doc/html/rfc5685 RFC 5685]
| [https://tools.ietf.org/html/rfc6027 RFC 6027]
| Redirect Mechanism for IKEv2
| IPsec Cluster Problem Statement
| v3.28
|
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc5282 RFC 5282]
| Using Authenticated Encryption Algorithms with the Encrypted Payload of the IKEv2 Protocol
| v
| Only AES_GCM is implemented. AES_CCM requires support in the nss library
|-
| [https://datatracker.ietf.org/doc/html/rfc5026 RFC 5026]
| Mobile IPv6 Bootstrapping in Split Scenario
| -
| -
| [https://tools.ietf.org/html/rfc6290 RFC 6290]
| A Quick Crash Detection Method for the Internet Key Exchange Protocol (IKE)
|
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc4806 RFC 4806]
| Online Certificate Status Protocol (OCSP) Extensions to IKEv2
| -
| -
| [https://tools.ietf.org/html/rfc6311 RFC 6311]
| Regular OCSP fetching outside of IKE is supported.
| Protocol Support for High Availability of IKEv2/IPsec
|-
| [https://datatracker.ietf.org/doc/html/rfc4754 RFC 4754]
| IKE and IKEv2 Authentication Using the Elliptic Curve Digital Signature Algorithm (ECDSA)
| p
| Needs to be interop tested with Microsoft, see https://github.com/libreswan/libreswan/issues/659
|-
| [https://datatracker.ietf.org/doc/html/rfc4739 RFC 4739]
| Multiple Authentication Exchanges in the IKEv2 Protocol
| p
|
|
|-
|-
| -
| [https://datatracker.ietf.org/doc/html/rfc4621 RFC 4621]
| [https://tools.ietf.org/html/rfc6467 RFC 6467]
| Design of the IKEv2 Mobility and Multihoming (MOBIKE) Protocol
| Secure Password Framework for IKEv2
| N/A
|
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc4615 RFC 4615]
| The AES-Cipher-based Message Authentication Code-Pseudo-Random Function-128 (AES-CMAC-PRF-128) Algorithm for IKE
| p
| CMAC is supoorted as INTEG (for ESP/IKE) but not as PRF(for IKE) - this is pending support in the NSS library.
|-
| [https://datatracker.ietf.org/doc/html/rfc4595 RFC 4595]
| Use of IKEv2 in the Fibre Channel Security Association Management Protocol
| -
| -
| [https://tools.ietf.org/html/rfc6617 RFC 6617]
| Secure Pre-Shared Key (PSK) Authentication for the Internet Key Exchange Protocol (IKE)
|
|
|-
|-
| -
| [https://datatracker.ietf.org/doc/html/rfc4555 RFC 4555]
| [https://tools.ietf.org/html/rfc6628 RFC 6628]
| IKEv2 Mobility and Multihoming Protocol (MOBIKE)
| Efficient Augmented Password-Only Authentication and Key Exchange for IKEv2
| v
| "Additional Addresses" not supported
|-
| [https://datatracker.ietf.org/doc/html/rfc4478 RFC 4478]
| Repeated Authentication in Internet Key Exchange (IKEv2) Protocol
| p
|
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc4307 RFC 4307]
| Cryptographic Algorithms for Use in the Internet Key Exchange Version 2 (IKEv2)
| v
| Obsoleted by [https://datatracker.ietf.org/doc/html/rfc8247 RFC 8247]
|-
| [https://datatracker.ietf.org/doc/html/draft-brunner-ikev2-mediation draft-brunner-ikev2-mediation]
| IKEv2 Mediation Extension
| -
| -
| [https://tools.ietf.org/html/rfc6631 RFC 6631]
| Password Authenticated Connection Establishment with IKEv2
|
|
|-
|-
| [https://datatracker.ietf.org/doc/html/draft-laganier-ike-ipv6-cga draft-laganier-ike-ipv6-cga]
| Using IKE with IPv6 Cryptographically Generated Addresses
| -
| -
| [https://tools.ietf.org/html/rfc6867 RFC 6867]
| An Internet Key Exchange Protocol Version 2 (IKEv2) Extension to Support EAP Re-authentication Protocol (ERP)
|
|
|-
|-
| -
| [https://datatracker.ietf.org/doc/html/draft-ietf-ipsecme-split-dns draft-ietf-ipsecme-split-dns]
| [https://tools.ietf.org/html/rfc6932 RFC 6932]
| Split DNS Configuration for IKEv2
| Brainpool Elliptic Curves for the IKE Group Description Registry
| p
| INTERNAL_DOMAIN implemented, INTERNAL_TA_DNSSEC not yet implemented
|-
| [https://datatracker.ietf.org/doc/html/draft-smyslov-ipsecme-ikev2-auth-announce draft-ietf-ipsecme-ikev2-auth-announce]
| Announcing Supported Authentication Methods in IKEv2
|
| Internet-Draft
|-
| [https://datatracker.ietf.org/doc/draft-pwouters-ipsecme-multi-sa-performance draft-pwouters-ipsecme-multi-sa-performance]
| IKEv2 support for per-queue Child SAs
|
| Internet-Draft
|-
| [https://datatracker.ietf.org/doc/draft-smyslov-ipsecme-ikev2-qr-alt draft-smyslov-ipsecme-ikev2-qr-alt]
| Alternative Approach for Mixing Preshared Keys in IKEv2 for Post-quantum Security
|
| Internet-Draft
|-
| [https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-sa-ts-payloads-opt draft-ietf-ipsecme-ikev2-sa-ts-payloads-opt]
| IKEv2 Optional SA&TS Payloads in Child Exchange
|
| Internet-Draft
|-
|}
 
== IKEv1 ==
 
{| class="wikitable"
! style="text-align:left;" | Standard
! style="text-align:left;" | Description
! style="text-align:left;" | Status
! style="text-align:left;" | Comments
|-
| [https://datatracker.ietf.org/doc/html/4304 RFC 4304]
| Extended Sequence Number (ESN) Addendum to IPsec Domain of Interpretation (DOI) for Internet Security Association and Key Management Protocol (ISAKMP)
|
|
|-
| [https://datatracker.ietf.org/doc/html/3947 RFC 3947]
| Negotiation of NAT-Traversal in the IKE
| v
| known as "NATT" or "ESPinUDP"
|-
| [https://datatracker.ietf.org/doc/html/rfc3706 RFC 3706]
| A Traffic-Based Method of Detecting Dead Internet Key Exchange (IKE) Peers
| v
| known as "DPD"; IKEv2's equivalent is "liveness"
|-
| [https://datatracker.ietf.org/doc/html/rfc3526 RFC 3526]
| More Modular Exponential (MODP) Diffie-Hellman groups
| v
|
|
|-
|-
| -
| [http://datatracker.ietf.org/doc/html/rfc2409 RFC 2409]
| [https://tools.ietf.org/html/rfc6954 RFC 6954]
| '''Internet Key Exchange (IKE)'''
| Using the Elliptic Curve Cryptography (ECC) Brainpool Curves for the Internet Key Exchange Protocol Version 2 (IKEv2)
| v
|  
| Revised Mode not implemented
|-
|-
| N/A
| [http://datatracker.ietf.org/doc/html/rfc2408 RFC 2408]
| [https://tools.ietf.org/html/rfc6989 RFC 6989]
| '''Internet Security Association and Key Management Protocol (ISAKMP)'''
| Additional Diffie-Hellman Tests for the Internet Key Exchange Protocol Version 2 (IKEv2)
| v
| This work is or needs to be done inside the nss library
|
|-
|-
|v
| [http://datatracker.ietf.org/doc/html/rfc2407 RFC 2407]
| [https://tools.ietf.org/html/rfc7383 RFC 7383]
| '''IPsec Domain of Interpretation for ISAKMP (IPsec DoI)'''
| Internet Key Exchange Protocol Version 2 (IKEv2) Message Fragmentation
| v
|
|
|-
|-
|v
| [http://datatracker.ietf.org/doc/html/draft-dukes-ike-mode-cfg draft-dukes-ike-mode-cfg]
| [https://tools.ietf.org/html/rfc7427 RFC 7427]
| The ISAKMP Configuration Method
| Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)
| v
| Initial implementation only supports RSA-v1.5. More planned in near future
|
|-
|-
|v
| [http://datatracker.ietf.org/doc/html/draft-ietf-ipsec-isakmp-xauth draft-ietf-ipsec-isakmp-xauth]
| [https://tools.ietf.org/html/rfc7619 RFC 7619]
| Extended Authentication within ISAKMP/Oakley (XAUTH)
| The NULL Authentication Method in the Internet Key Exchange Protocol Version 2 (IKEv2)
| v
|
|
|-
|-
|v
| [http://datatracker.ietf.org/doc/html/draft-jenkins-ipsec-rekeying-06 draft-jenkins-ipsec-rekeying]
| [https://tools.ietf.org/html/rfc7634 RFC 7634]
| IPsec Re-keying Issues
| ChaCha20, Poly1305, and Their Use in the IKE Protocol and IPsec
| v
| Added in 3.26
| Implementation differs on some point but accomplishes the same
|-
|-
| -
| [http://datatracker.ietf.org/doc/html/draft-ietf-ipsec-isakmp-hybrid-auth  draft-ietf-ipsec-isakmp-hybrid-auth]
| [https://tools.ietf.org/html/rfc7651 RFC 7651]
| A Hybrid Authentication Mode for IKE
| 3GPP IP Multimedia Subsystems (IMS) Option for the Internet Key Exchange Protocol Version 2 (IKEv2)
| '''X'''
|
|
|-
|-
|p
|}
| [https://tools.ietf.org/html/rfc7670 RFC 7670]
 
| Generic Raw Public-Key Support for IKEv2
== IPsec ==
| raw RSA public keys are supported using the core IKE RFCs
 
{| class="wikitable"
! style="text-align:left;" | Standard
! style="text-align:left;" | Description
! style="text-align:left;" | Status
! style="text-align:left;" | Comments
|-
| [https://datatracker.ietf.org/doc/html/rfc4302 RFC 4302 ]
| '''IP Authentication Header (AH)'''
| v
| Obsoletes: [https://datatracker.ietf.org/doc/html/rfc2402 2402]
|-
| [https://datatracker.ietf.org/doc/html/rfc4303 RFC 4303 ]
| '''IP Encapsulating Security Payload (ESP)'''
| v
| Obsoletes: [https://datatracker.ietf.org/doc/html/rfc2406 2406]
|-
|
|
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc8750 RFC 8750]
| Implicit Initialization Vector (IV) for Counter-Based Ciphers in Encapsulating Security Payload (ESP)
| -
| -
| [https://tools.ietf.org/html/rfc8019 RFC 8019]  
|
| Protecting Internet Key Exchange Protocol Version 2 (IKEv2) Implementations from Distributed Denial-of-Service Attacks
|-
| [https://datatracker.ietf.org/doc/html/rfc8221 RFC 8221]
| Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)
| v
| Obsoletes [http://datatracker.ietf.org/doc/html/rfc7321 RFC 7321]
|-
| [https://datatracker.ietf.org/doc/html/rfc7321 RFC 7321]
| Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)
| v
| Obsoleted by [http://datatracker.ietf.org/doc/html/rfc8221 RFC 8221]
|-
| [https://datatracker.ietf.org/doc/html/rfc7018 RFC 7018 ]
| Auto-Discovery VPN Problem Statement and Requirements
| N/A
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc6479 RFC 6479 ]  
| [https://tools.ietf.org/html/rfc8247 RFC 8247]
| IPsec Anti-Replay Algorithm without Bit Shifting
| Algorithm Implementation Requirements and Usage Guidance for the Internet Key Exchange Protocol Version 2 (IKEv2)
| ?
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc6379 RFC 6379 ]  
| [https://tools.ietf.org/html/rfc8229 RFC 8229]
| Suite B Cryptographic Suites for IPsec
| TCP Encapsulation of IKE and IPsec Packets
| v
| IKE over TCP implemented - waiting on Linux kernel for ESP over TCP implementation. Does not currently support IKE/ESP over TLS
| Not all ciphers are implemented
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc6380 RFC 6380 ]
| Suite B Profile for Internet Protocol Security (IPsec)
| v
| v
| [https://datatracker.ietf.org/doc/rfc8784/ RFC 8784]
|
| Postquantum Preshared Keys for IKEv2
| Added in 3.25
|-
|-
| -
| [https://datatracker.ietf.org/doc/html/rfc5879 RFC 5879 ]
| [https://tools.ietf.org/html/draft-brunner-ikev2-mediation draft-brunner-ikev2-mediation]
| Heuristics for Detecting ESP-NULL Packets
| IKEv2 Mediation Extension
| N/A
|
|
|-
|-
| -
| [https://datatracker.ietf.org/doc/html/rfc5840 RFC 5840 ]  
| [https://tools.ietf.org/html/draft-laganier-ike-ipv6-cga draft-laganier-ike-ipv6-cga]
| Wrapped Encapsulating Security Payload (ESP) for Traffic Visibility
| Using IKE with IPv6 Cryptographically Generated Addresses
| '''X'''
|
|
|-
|-
| p
| [https://datatracker.ietf.org/doc/html/rfc5660 RFC 5660 ]  
| [https://tools.ietf.org/html/draft-ietf-ipsecme-split-dns draft-ietf-ipsecme-split-dns]
| IPsec Channels: Connection Latching
| Split DNS Configuration for IKEv2
| '''X'''
| INTERNAL_DOMAIN implemented, INTERNAL_TA_DNSSEC not yet implemented
|  
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc5529 RFC 5529 ]  
| [https://tools.ietf.org/html/draft-ietf-ipsecme-ikev2-intermediate-03 draft-ietf-ipsecme-ikev2-intermediate-03]
| Modes of Operation for Camellia for Use with IPsec
| Intermediate Exchange in the IKEv2 Protocol
| v
| Experimental
|
|-
|-
| colspan="4"| IPsec
| [https://datatracker.ietf.org/doc/html/rfc5114 RFC 5114 ]
| Additional Diffie-Hellman Groups for Use with IETF Standards
| v
| Only DH22,23,24 - remainder planned
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc4868 RFC 4868 ]
| Using HMAC-SHA-256, HMAC-SHA-384, and HMAC-SHA-512 with IPsec
| v
| v
| [https://tools.ietf.org/html/rfc4301 RFC 4301 ]
| Security Architecture for the Internet Protocol
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc4543 RFC 4543 ]  
| [https://tools.ietf.org/html/rfc4302 RFC 4302 ]
| The Use of Galois Message Authentication Code (GMAC) in IPsec ESP and AH
| IP Authentication Header (AH)
| '''X'''
| Kernel support is availble, ike support is not
|-
| [https://datatracker.ietf.org/doc/html/rfc4494 RFC 4494 ]
| The AES-CMAC-96 Algorithm and Its Use with IPsec
| '''X'''
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc4309 RFC 4309 ]  
| [https://tools.ietf.org/html/rfc4303 RFC 4303 ]
| Using Advanced Encryption Standard (AES) CCM Mode with IPsec ESP
| IP Encapsulating Security Payload (ESP)
| v
|
|
|-
|-
| [https://datatracker.ietf.org/doc/html/rfc4308 RFC 4308 ]
| Cryptographic Suites for IPsec
|
|
| [https://tools.ietf.org/html/rfc4308 RFC 4308 ]
| Cryptographic Suites for IPsec
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc4304 RFC 4304 ]  
| [https://tools.ietf.org/html/rfc7321 RFC 7321 ]
| Extended Sequence Number (ESN) Addendum to IPsec DOI for ISAKMP
| Cryptographic Algorithm Implementation Requirements and Usage Guidance for ESP and AH Extensions
| v
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc4303 RFC 4303 ]
| [https://tools.ietf.org/html/rfc2410 RFC 2410 ]
| '''IP Encapsulating Security Payload (ESP)'''
| The NULL Encryption Algorithm and Its Use With IPsec
| v
|
| Obsoletes: [https://datatracker.ietf.org/doc/html/rfc2406 2406]
|-
| [https://datatracker.ietf.org/doc/html/rfc4302 RFC 4302 ]
| '''IP Authentication Header (AH)'''
| v
| Obsoletes: [https://datatracker.ietf.org/doc/html/rfc2402 2402]
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc4301 RFC 4301 ]
| [https://tools.ietf.org/html/rfc2451 RFC 2451 ]  
| Security Architecture for the Internet Protocol
| The ESP CBC-Mode Cipher Algorithms
| v
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc4106 RFC 4106 ]  
| [https://tools.ietf.org/html/rfc3602 RFC 3602 ]  
| The Use of Galois/Counter Mode (GCM) in IPsec ESP
| The AES-CBC Cipher Algorithm and Its Use with IPsec
| v
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc3948 RFC 3948 ]  
| [https://tools.ietf.org/html/rfc3948 RFC 3948 ]  
| UDP Encapsulation of IPsec ESP Packets
| UDP Encapsulation of IPsec ESP Packets
| v
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc3686 RFC 3686 ]  
| [https://tools.ietf.org/html/rfc3686 RFC 3686 ]  
| Using Advanced Encryption Standard (AES) Counter Mode With IPsec Encapsulating Security Payload (ESP)
| Using Advanced Encryption Standard (AES) Counter Mode With IPsec Encapsulating Security Payload (ESP)
| v
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc3602 RFC 3602 ]  
| [https://tools.ietf.org/html/rfc4106 RFC 4106 ]  
| The AES-CBC Cipher Algorithm and Its Use with IPsec
| The Use of Galois/Counter Mode (GCM) in IPsec ESP
| v
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc2451 RFC 2451 ]  
| [https://tools.ietf.org/html/rfc4304 RFC 4304 ]  
| The ESP CBC-Mode Cipher Algorithms
| Extended Sequence Number (ESN) Addendum to IPsec DOI for ISAKMP
| v
|
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc2410 RFC 2410 ]
| [https://tools.ietf.org/html/rfc4309 RFC 4309 ]  
| The NULL Encryption Algorithm and Its Use With IPsec
| Using Advanced Encryption Standard (AES) CCM Mode with IPsec ESP
| v
|
|
|-
|-
|x
| [https://datatracker.ietf.org/doc/html/draft-antony-ipsecme-oppo-nat draft-antony-ipsecme-oppo-nat]
| [https://tools.ietf.org/html/rfc4494 RFC 4494 ]  
| NAT-Traversal support for Opportunistic IPsec
| The AES-CMAC-96 Algorithm and Its Use with IPsec
| v
|
| Experimental
|-
| [https://datatracker.ietf.org/doc/html/draft-nikander-esp-beet-mode draft-nikander-esp-beet-mode]
| A Bound End-to-End Tunnel (BEET) mode for ESP
| '''X'''
| Never ratified, but it is the scenario where a Linux kernel state's selector does not match the state's src/dst address.
|}
 
== EAP ==
 
{| class="wikitable"
! style="text-align:left;" | Standard
! style="text-align:left;" | Description
! style="text-align:left;" | Status
! style="text-align:left;" | Comments
|-
| [https://datatracker.ietf.org/doc/html/rfc9190 RFC-9190]
| EAP-TLS 1.3: Using the Extensible Authentication Protocol with TLS 1.3
| v4.7
|
|-
| [https://datatracker.ietf.org/doc/html/rfc5998 RFC-5998]
| An Extension for EAP-Only Authentication in IKEv2
| v4.7?
|
|-
| [https://datatracker.ietf.org/doc/html/rfc5216 RFC-5216]
| The EAP-TLS Authentication Protocol
|
| Updated by RFC-9190
|-
|-
|x
| [https://datatracker.ietf.org/doc/html/rfc3748 RFC-3748]
| [https://tools.ietf.org/html/rfc4543 RFC 4543 ]  
| Extensible Authentication Protocol (EAP)
| The Use of Galois Message Authentication Code (GMAC) in IPsec ESP and AH
|  
| Kernel support is availble, ike support is not
|
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc2716 RFC-2716]
| [https://tools.ietf.org/html/rfc4868 RFC 4868 ]  
| PPP EAP TLS Authentication Protocol
| Using HMAC-SHA-256, HMAC-SHA-384, and HMAC-SHA-512 with IPsec
|
|
| Obsoleted by RFC-5216
|}
 
== PF KEY V2 ==
 
* most BSD derived systems implement a flavour of PF KEY v2 using the [https://www.kame.net/ KAME] code base as a starting point
* even Linux, which implements XFRM, has borrowed concepts from PF KEY v2
 
{| class="wikitable"
! style="text-align:left;" | Standard
! style="text-align:left;" | Description
! style="text-align:left;" | Status
! style="text-align:left;" | Comments
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc2367 RFC-2367]
| [https://tools.ietf.org/html/rfc5114 RFC 5114 ]  
| PF_KEY Key Management API, Version 2
| Additional Diffie-Hellman Groups for Use with IETF Standards
| v4.7
| Only DH22,23,24 - remainder planned
| SADB messages to set up kernel state on BSD machines
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/draft-schilcher-mobike-pfkey-extension-01 draft-schilcher-mobike-pfkey-extension-01]
| [https://tools.ietf.org/html/rfc5529 RFC 5529 ]  
| MOBIKE Extensions for PF_KEY
| Modes of Operation for Camellia for Use with IPsec
| v4.7
|
| also defines KAME's SPD extensions to set up kernel policy on BSD machine
|-
|-
|X
| [https://www.kame.net/newsletter/20021210/ PF_KEY Extensions for IPsec Policy Management in KAME Stack]
| [https://tools.ietf.org/html/rfc5660 RFC 5660 ]  
| Post to KAME mailing list about PF KEY
| IPsec Channels: Connection Latching
|  
|  
| Some background
|}
== Cryptography: AEAD, Public Keys (formats, standards, DNS records) ... ==
{| class="wikitable"
! style="text-align:left;" | Standard
! style="text-align:left;" | Description
! style="text-align:left;" | Status
! style="text-align:left;" | Comments
|-
|-
| N/A
| [https://datatracker.ietf.org/doc/html/rfc8813 RFC-8813]
| [https://tools.ietf.org/html/rfc5879 RFC 5879 ]  
| Clarifications for Elliptic Curve Cryptography Subject Public Key Information
| Heuristics for Detecting ESP-NULL Packets
|
|
|
|-
|-
|X
| [https://datatracker.ietf.org/doc/html/rfc7468 RFC-7468]
| [https://tools.ietf.org/html/rfc5840 RFC 5840 ]  
| Textual Encodings of PKIX, PKCS, and CMS Structures
| Wrapped Encapsulating Security Payload (ESP) for Traffic Visibility
| v
| ipsec showhostkey --pem: outputs [https://datatracker.ietf.org/doc/html/rfc7468#section-13 13. Textual Encoding of Subject Public Key Info]
|-
| [https://datatracker.ietf.org/doc/html/rfc6605 RFC-6605]
| Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC
|
|
| "ipsec --ipseckey" and "ipseckey --{left,right}" both dump ECDSA keys using the format described in [https://datatracker.ietf.org/doc/html/rfc6605#section-4 4. DNSKEY and RRSIG Resource Records for ECDSA]
|-
| [https://datatracker.ietf.org/doc/html/rfc5280 RFC-5280]
| Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile
|
| See [https://datatracker.ietf.org/doc/html/rfc5280#section-4.1.2.7 4.1.2.7. Subject Public Key Info]
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc4648 RFC-4648]
| [https://tools.ietf.org/html/rfc6379 RFC 6379 ]  
| The Base16, Base32, and Base64 Data Encodings
| Suite B Cryptographic Suites for IPsec
| v
| Not all ciphers are implemented
| see datatot()
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc4034 RFC-4034]
| [https://tools.ietf.org/html/rfc6380 RFC 6380 ]  
| Resource Records for the DNS Security Extensions
| Suite B Profile for Internet Protocol Security (IPsec)
|
|
|  
|-
|-
|?
| [https://datatracker.ietf.org/doc/html/rfc4025 RFC-4025]
| [https://tools.ietf.org/html/rfc6479 RFC 6479 ]  
| A Method for Storing IPsec Keying Material in DNS
| IPsec Anti-Replay Algorithm without Bit Shifting
| v
|
| ipsec showhostkey --ipseckey: outputs the text for an IPSECKEY RR record<br>Algorithm 1, DSA: [https://datatracker.ietf.org/doc/html/rfc2536#section-2 2. DSA KEY Resource Records]<br>Algorithm 2, RSA: [https://datatracker.ietf.org/doc/html/rfc3110#section-2 RFC-3110 2. RSA Public KEY Resource Records]<br>Algorithm 3, ECDSA: [https://datatracker.ietf.org/doc/html/rfc6605#section-4 RFC-6605 4.  DNSKEY and RRSIG Resource Records for ECDSA]<br>Algorithm 4 will probably use [https://datatracker.ietf.org/doc/html/rfc5280#section-4.1.2.7 RFC-5280 4.1.2.7. Subject Public Key Info]
|-
|-
|N/A
| [https://datatracker.ietf.org/doc/html/rfc3110 RFC-3110]
| [https://tools.ietf.org/html/rfc7018 RFC 7018 ]  
| RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS)
| Auto-Discovery VPN Problem Statement and Requirements
| v
|
| "ipsec --ipseckey" and "ipseckey --{left,right}" dump RSA keys using the format described in [https://datatracker.ietf.org/doc/html/rfc3110#section-2 2. RSA Public KEY Resource Records].
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc2536 RFC-2536]
| [https://tools.ietf.org/html/rfc7321 RFC 7321]
| DSA KEYs and SIGs in the Domain Name System (DNS)
| Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)
|  
| Obsoleted by [http://tools.ietf.org/html/rfc8221 RFC 8221]
| This won't be implemented.
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/rfc1421 RFC-1421]
| [https://tools.ietf.org/html/rfc8221 RFC 8221]
| Privacy Enhancement for Internet Electronic Mail: Part I: Message Encryption and Authentication Procedures
| Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)
|  
| Obsoletes [http://tools.ietf.org/html/rfc7321 RFC 7321]
| Origins of PEM format.
|-
|-
|v
| [https://datatracker.ietf.org/doc/html/html/draft-irtf-cfrg-aead-limits draft-irtf-cfrg-aead-limits]
| [https://tools.ietf.org/html/draft-antony-ipsecme-oppo-nat draft-antony-ipsecme-oppo-nat]
| Usage Limits on AEAD Algorithms
| NAT-Traversal support for Opportunistic IPsec
|
| Experimental
| Hopefully answers the question of what limits to place on AEAD.
|}
|}

Latest revision as of 15:38, 12 June 2024

The following table lists the RFCs, drafts and standards related to IKE and IPsec. An overview of IKE and IPsec related RFC's is available in RFC 6071.

Implementation status can be: implemented (yes, vX.X), planned (p), not implemented (-), will not be implemented (X) and work in progress (wip)

All the standards, including drafts can be found at IP Security Maintenance and Extensions

IKEv2 RFC 7296

Standard Description Status Comments
RFC 9478 Labeled IPsec Traffic Selector support for IKEv2 v4.4
RFC 9464 Configuration for Encrypted DNS
RFC 9370 Intermediate Exchange in the IKEv2 Protocol aka IKE_INTERMEDIATE + IKE_FOLLOWUP_KE
RFC 9347 Aggregation and Fragmentation Mode for Encapsulating Security Payload (ESP) and Its Use for IP Traffic Flow Security (IP-TFS) p
RFC 9242 Intermediate Exchange in the IKEv2 Protocol v aka IKE_INTERMEDIATE
RFC 8784 Postquantum Preshared Keys for IKEv2 v3.25
RFC 8420 Using the Edwards-Curve Digital Signature Algorithm (EdDSA) in the Internet Key Exchange Protocol Version 2 (IKEv2) wip Code is available in a branch, but requires NSS patches - waiting on NSS merge before merging into libreswan
RFC 8247 Algorithm Implementation Requirements and Usage Guidance for the Internet Key Exchange Protocol Version 2 (IKEv2) v
RFC 8229 TCP Encapsulation of IKE and IPsec Packets v4.0 IKE over TCP implemented and IKE over ESP supported on Linux 5.6+ kernels. Does not currently support IKE/ESP over TLS
RFC 8019 Protecting Internet Key Exchange Protocol Version 2 (IKEv2) Implementations from Distributed Denial-of-Service Attacks -
RFC 7815 Minimal Internet Key Exchange Version 2 (IKEv2) Initiator Implementation X This is a really just a subset of IKEv2 RFC 7296
RFC 7670 Generic Raw Public-Key Support for IKEv2 p raw RSA public keys are supported using the core IKE RFCs
RFC 7651 3GPP IP Multimedia Subsystems (IMS) Option for the Internet Key Exchange Protocol Version 2 (IKEv2) -
RFC 7634 ChaCha20, Poly1305, and Their Use in the IKE Protocol and IPsec v3.26
RFC 7619 The NULL Authentication Method in the Internet Key Exchange Protocol Version 2 (IKEv2) v
RFC 7427 Signature Authentication in the Internet Key Exchange Version 2 (IKEv2) v a.k.a. DIGSIG
Implementation supports RSS-PSS (v3.26) and ECDSA(v3.26) and RSA-v1.5 (v4.7)
RFC 7383 Internet Key Exchange Protocol Version 2 (IKEv2) Message Fragmentation v
RFC 7296 Internet Key Exchange Protocol Version 2 (IKEv2) v Obsoletes RFC 5996 and RFC 4718
RFC 6989 Additional Diffie-Hellman Tests for the Internet Key Exchange Protocol Version 2 (IKEv2) N/A This work is or needs to be done inside the nss library
RFC 6954 Using the Elliptic Curve Cryptography (ECC) Brainpool Curves for the Internet Key Exchange Protocol Version 2 (IKEv2) -
RFC 6932 Brainpool Elliptic Curves for the IKE Group Description Registry -
RFC 6867 An Internet Key Exchange Protocol Version 2 (IKEv2) Extension to Support EAP Re-authentication Protocol (ERP) -
RFC 6631 Password Authenticated Connection Establishment with IKEv2 -
RFC 6628 Efficient Augmented Password-Only Authentication and Key Exchange for IKEv2 -
RFC 6617 Secure Pre-Shared Key (PSK) Authentication for the Internet Key Exchange Protocol (IKE) -
RFC 6467 Secure Password Framework for IKEv2 -
RFC 6311 Protocol Support for High Availability of IKEv2/IPsec -
RFC 6290 A Quick Crash Detection Method for the Internet Key Exchange Protocol (IKE) p
RFC 6027 IPsec Cluster Problem Statement N/A
RFC 6023 A Childless Initiation of the Internet Key Exchange Version 2 (IKEv2) Security Association (SA) -
RFC 5998 An Extension for EAP-only Authentication in IKEv2 wip
RFC 5930 Using Advanced Encryption Standard Counter Mode (AES-CTR) with the Internet Key Exchange version 02 (IKEv2) Protocol v
RFC 5903 ECP Groups for IKE and IKEv2 v
RFC 5857 IKEv2 Extensions to Support Robust Header Compression over IPsec -
RFC 5739 IPv6 Configuration in Internet Key Exchange Protocol Version 2 (IKEv2) -
RFC 5723 Internet Key Exchange Protocol Version 2 (IKEv2) Session Resumption wip
RFC 5685 Redirect Mechanism for IKEv2 v3.28
RFC 5282 Using Authenticated Encryption Algorithms with the Encrypted Payload of the IKEv2 Protocol v Only AES_GCM is implemented. AES_CCM requires support in the nss library
RFC 5026 Mobile IPv6 Bootstrapping in Split Scenario -
RFC 4806 Online Certificate Status Protocol (OCSP) Extensions to IKEv2 - Regular OCSP fetching outside of IKE is supported.
RFC 4754 IKE and IKEv2 Authentication Using the Elliptic Curve Digital Signature Algorithm (ECDSA) p Needs to be interop tested with Microsoft, see https://github.com/libreswan/libreswan/issues/659
RFC 4739 Multiple Authentication Exchanges in the IKEv2 Protocol p
RFC 4621 Design of the IKEv2 Mobility and Multihoming (MOBIKE) Protocol N/A
RFC 4615 The AES-Cipher-based Message Authentication Code-Pseudo-Random Function-128 (AES-CMAC-PRF-128) Algorithm for IKE p CMAC is supoorted as INTEG (for ESP/IKE) but not as PRF(for IKE) - this is pending support in the NSS library.
RFC 4595 Use of IKEv2 in the Fibre Channel Security Association Management Protocol -
RFC 4555 IKEv2 Mobility and Multihoming Protocol (MOBIKE) v "Additional Addresses" not supported
RFC 4478 Repeated Authentication in Internet Key Exchange (IKEv2) Protocol p
RFC 4307 Cryptographic Algorithms for Use in the Internet Key Exchange Version 2 (IKEv2) v Obsoleted by RFC 8247
draft-brunner-ikev2-mediation IKEv2 Mediation Extension -
draft-laganier-ike-ipv6-cga Using IKE with IPv6 Cryptographically Generated Addresses -
draft-ietf-ipsecme-split-dns Split DNS Configuration for IKEv2 p INTERNAL_DOMAIN implemented, INTERNAL_TA_DNSSEC not yet implemented
draft-ietf-ipsecme-ikev2-auth-announce Announcing Supported Authentication Methods in IKEv2 Internet-Draft
draft-pwouters-ipsecme-multi-sa-performance IKEv2 support for per-queue Child SAs Internet-Draft
draft-smyslov-ipsecme-ikev2-qr-alt Alternative Approach for Mixing Preshared Keys in IKEv2 for Post-quantum Security Internet-Draft
draft-ietf-ipsecme-ikev2-sa-ts-payloads-opt IKEv2 Optional SA&TS Payloads in Child Exchange Internet-Draft

IKEv1

Standard Description Status Comments
RFC 4304 Extended Sequence Number (ESN) Addendum to IPsec Domain of Interpretation (DOI) for Internet Security Association and Key Management Protocol (ISAKMP)
RFC 3947 Negotiation of NAT-Traversal in the IKE v known as "NATT" or "ESPinUDP"
RFC 3706 A Traffic-Based Method of Detecting Dead Internet Key Exchange (IKE) Peers v known as "DPD"; IKEv2's equivalent is "liveness"
RFC 3526 More Modular Exponential (MODP) Diffie-Hellman groups v
RFC 2409 Internet Key Exchange (IKE) v Revised Mode not implemented
RFC 2408 Internet Security Association and Key Management Protocol (ISAKMP) v
RFC 2407 IPsec Domain of Interpretation for ISAKMP (IPsec DoI) v
draft-dukes-ike-mode-cfg The ISAKMP Configuration Method v
draft-ietf-ipsec-isakmp-xauth Extended Authentication within ISAKMP/Oakley (XAUTH) v
draft-jenkins-ipsec-rekeying IPsec Re-keying Issues v Implementation differs on some point but accomplishes the same
draft-ietf-ipsec-isakmp-hybrid-auth A Hybrid Authentication Mode for IKE X

IPsec

Standard Description Status Comments
RFC 4302 IP Authentication Header (AH) v Obsoletes: 2402
RFC 4303 IP Encapsulating Security Payload (ESP) v Obsoletes: 2406
RFC 8750 Implicit Initialization Vector (IV) for Counter-Based Ciphers in Encapsulating Security Payload (ESP) -
RFC 8221 Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH) v Obsoletes RFC 7321
RFC 7321 Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH) v Obsoleted by RFC 8221
RFC 7018 Auto-Discovery VPN Problem Statement and Requirements N/A
RFC 6479 IPsec Anti-Replay Algorithm without Bit Shifting ?
RFC 6379 Suite B Cryptographic Suites for IPsec v Not all ciphers are implemented
RFC 6380 Suite B Profile for Internet Protocol Security (IPsec) v
RFC 5879 Heuristics for Detecting ESP-NULL Packets N/A
RFC 5840 Wrapped Encapsulating Security Payload (ESP) for Traffic Visibility X
RFC 5660 IPsec Channels: Connection Latching X
RFC 5529 Modes of Operation for Camellia for Use with IPsec v
RFC 5114 Additional Diffie-Hellman Groups for Use with IETF Standards v Only DH22,23,24 - remainder planned
RFC 4868 Using HMAC-SHA-256, HMAC-SHA-384, and HMAC-SHA-512 with IPsec v
RFC 4543 The Use of Galois Message Authentication Code (GMAC) in IPsec ESP and AH X Kernel support is availble, ike support is not
RFC 4494 The AES-CMAC-96 Algorithm and Its Use with IPsec X
RFC 4309 Using Advanced Encryption Standard (AES) CCM Mode with IPsec ESP v
RFC 4308 Cryptographic Suites for IPsec
RFC 4304 Extended Sequence Number (ESN) Addendum to IPsec DOI for ISAKMP v
RFC 4303 IP Encapsulating Security Payload (ESP) v Obsoletes: 2406
RFC 4302 IP Authentication Header (AH) v Obsoletes: 2402
RFC 4301 Security Architecture for the Internet Protocol v
RFC 4106 The Use of Galois/Counter Mode (GCM) in IPsec ESP v
RFC 3948 UDP Encapsulation of IPsec ESP Packets v
RFC 3686 Using Advanced Encryption Standard (AES) Counter Mode With IPsec Encapsulating Security Payload (ESP) v
RFC 3602 The AES-CBC Cipher Algorithm and Its Use with IPsec v
RFC 2451 The ESP CBC-Mode Cipher Algorithms v
RFC 2410 The NULL Encryption Algorithm and Its Use With IPsec v
draft-antony-ipsecme-oppo-nat NAT-Traversal support for Opportunistic IPsec v Experimental
draft-nikander-esp-beet-mode A Bound End-to-End Tunnel (BEET) mode for ESP X Never ratified, but it is the scenario where a Linux kernel state's selector does not match the state's src/dst address.

EAP

Standard Description Status Comments
RFC-9190 EAP-TLS 1.3: Using the Extensible Authentication Protocol with TLS 1.3 v4.7
RFC-5998 An Extension for EAP-Only Authentication in IKEv2 v4.7?
RFC-5216 The EAP-TLS Authentication Protocol Updated by RFC-9190
RFC-3748 Extensible Authentication Protocol (EAP)
RFC-2716 PPP EAP TLS Authentication Protocol Obsoleted by RFC-5216

PF KEY V2

  • most BSD derived systems implement a flavour of PF KEY v2 using the KAME code base as a starting point
  • even Linux, which implements XFRM, has borrowed concepts from PF KEY v2
Standard Description Status Comments
RFC-2367 PF_KEY Key Management API, Version 2 v4.7 SADB messages to set up kernel state on BSD machines
draft-schilcher-mobike-pfkey-extension-01 MOBIKE Extensions for PF_KEY v4.7 also defines KAME's SPD extensions to set up kernel policy on BSD machine
PF_KEY Extensions for IPsec Policy Management in KAME Stack Post to KAME mailing list about PF KEY Some background


Cryptography: AEAD, Public Keys (formats, standards, DNS records) ...

Standard Description Status Comments
RFC-8813 Clarifications for Elliptic Curve Cryptography Subject Public Key Information
RFC-7468 Textual Encodings of PKIX, PKCS, and CMS Structures v ipsec showhostkey --pem: outputs 13. Textual Encoding of Subject Public Key Info
RFC-6605 Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC "ipsec --ipseckey" and "ipseckey --{left,right}" both dump ECDSA keys using the format described in 4. DNSKEY and RRSIG Resource Records for ECDSA
RFC-5280 Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile See 4.1.2.7. Subject Public Key Info
RFC-4648 The Base16, Base32, and Base64 Data Encodings v see datatot()
RFC-4034 Resource Records for the DNS Security Extensions
RFC-4025 A Method for Storing IPsec Keying Material in DNS v ipsec showhostkey --ipseckey: outputs the text for an IPSECKEY RR record
Algorithm 1, DSA: 2. DSA KEY Resource Records
Algorithm 2, RSA: RFC-3110 2. RSA Public KEY Resource Records
Algorithm 3, ECDSA: RFC-6605 4. DNSKEY and RRSIG Resource Records for ECDSA
Algorithm 4 will probably use RFC-5280 4.1.2.7. Subject Public Key Info
RFC-3110 RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS) v "ipsec --ipseckey" and "ipseckey --{left,right}" dump RSA keys using the format described in 2. RSA Public KEY Resource Records.
RFC-2536 DSA KEYs and SIGs in the Domain Name System (DNS) This won't be implemented.
RFC-1421 Privacy Enhancement for Internet Electronic Mail: Part I: Message Encryption and Authentication Procedures Origins of PEM format.
draft-irtf-cfrg-aead-limits Usage Limits on AEAD Algorithms Hopefully answers the question of what limits to place on AEAD.