IP Security Protocol (ipsec)

This Working Group did not meet

Last Modified: 2003-04-10

Chair(s):
Barbara Fraser <byfraser@cisco.com>
Theodore Ts'o <tytso@mit.edu>
Security Area Director(s):
Russell Housley <housley@vigilsec.com>
Steven Bellovin <smb@research.att.com>
Security Area Advisor:
Russell Housley <housley@vigilsec.com>
Technical Advisor(s):
Uri Blumenthal <uri@lucent.com>
Mailing Lists:
General Discussion: ipsec@lists.tislabs.com
To Subscribe: ipsec-request@lists.tislabs.com
Archive: ftp://ftp.tis.com/pub/lists/ipsec OR ftp.ans.net/pub/archive/ipsec
Description of Working Group:
Note: The Technical Advisor has the task to advice on technical
      matters related to all the MIB work in this WG.

Rapid advances in communication technology have accentuated the need
for security in the Internet.  The IP Security Protocol Working Group
(IPSEC) will develop mechanisms to protect client protocols of IP.  A
security protocol in the network layer will be developed to provide
cryptographic security services that will flexibly support combinations
of authentication, integrity, access control, and confidentiality.

The IPSEC working group will restrict itself to the following
short-term work items to improve the existing key management protocol
(IKE) and IPSEC encapsulation protocols:

1. Changes to IKE to support NAT/Firewall traversal

2. Changes to IKE to support SCTP

3. New cipher documents to support AES-CBC, AES-MAC, SHA-2, and
  a fast AES mode suitable for use in hardware encryptors

4. IKE MIB documents

5. Sequence number extensions to ESP to support an expanded sequence
  number space.

6. Clarification and standardization of rekeying procedures in IKE.

The working group will also update IKE to clarify the specification and
to reflect implementation experience, new requirements, and protocol
analysis of the existing protocol.  The requirements for IKE V2 will be
revised and updated as the first step in this process.
Goals and Milestones:
Done  Post as an Internet-Draft the IP Security Protocol.
Done  Post as an Interenet-Draft the specification for Internet key management.
Done  Submit the Internet Key Management Protocol to the IESG for consideration as a Proposed Standard.
Done  Conduct initial interoperability testing of Encapsulating Security payload (ESP) and Authentication Header (AH).
Done  Submit revised Interent-Drafts for ESP, AH, and IP Security Architecture.
Done  Submit revised Internet-Drafts of IP Security Architecture, ESP, and AH to the IESG for consideration as Draft Standards.
Done  Submit Internet-Draft of the Internet Key Management Protocol (IKMP) based on ISAKMP/Oakley to the IESG for consideration as a Proposed Standard.
Done  Submit Internet-Draft of Internet Key Management Protocol to the IESG for consideration as a Proposed Standard.
Oct 01  Internet Drafts on NAT and Firewall traversal, IKE MIBs, and requirements for IPsec and IKE for use with SCTP, to working group last call.
Oct 01  Submit revised Internet-Drafts of NAT and Firewall traversal, IKE MIBs, and SCTP support for considerations as Draft Standards.
Nov 01  Internet-Drafts on sequence number expansion in IKE, and IKE re-keying completed.
Dec 01  Internet-Drafts on AES/SHA-2, sequence number expansion, and IKE re-keying to working group last call.
Dec 01  Internet-Draft on IKE v2 Requirements to working group last call
Dec 01  Internet-Drafts describing candidate IKE v2 approaches submitted to the working group.
Feb 02  Submit revised Internet-Drafts on AES/SHA-2, sequence number expansion, and IKE rekeying for consideration as Draft Standards.
Apr 02  Discuss and select the IKE v2 design from candidate approaches.
Sep 02  IKE
Dec 02  Submit
Internet-Drafts:
  • - draft-ietf-ipsec-esp-v3-06.txt
  • - draft-ietf-ipsec-monitor-mib-06.txt
  • - draft-ietf-ipsec-doi-tc-mib-07.txt
  • - draft-ietf-ipsec-isakmp-di-mon-mib-05.txt
  • - draft-ietf-ipsec-ike-monitor-mib-04.txt
  • - draft-ietf-ipsec-flow-monitoring-mib-02.txt
  • - draft-ietf-ipsec-ciph-aes-cbc-05.txt
  • - draft-ietf-ipsec-nat-reqts-05.txt
  • - draft-ietf-ipsec-nat-t-ike-06.txt
  • - draft-ietf-ipsec-udp-encaps-06.txt
  • - draft-ietf-ipsec-dpd-03.txt
  • - draft-ietf-ipsec-ikev2-10.txt
  • - draft-ietf-ipsec-ciph-aes-xcbc-mac-04.txt
  • - draft-ietf-ipsec-rfc2402bis-04.txt
  • - draft-ietf-ipsec-pki-profile-03.txt
  • - draft-ietf-ipsec-esn-addendum-02.txt
  • - draft-ietf-ipsec-ciph-aes-ctr-05.txt
  • - draft-ietf-ipsec-ikev2-ecnfix-01.txt
  • - draft-ietf-ipsec-ciph-aes-ccm-04.txt
  • - draft-ietf-ipsec-ikev2-tutorial-01.txt
  • - draft-ietf-ipsec-flowmon-mib-tc-00.txt
  • - draft-ietf-ipsec-dhcp-over-ike-00.txt
  • - draft-ietf-ipsec-dhcp-over-ike-dhcpd-00.txt
  • - draft-ietf-ipsec-dhcp-over-ike-radius-00.txt
  • - draft-ietf-ipsec-ikev2-algorithms-03.txt
  • - draft-ietf-ipsec-ui-suites-04.txt
  • - draft-ietf-ipsec-aes-xcbc-prf-00.txt
  • Request For Comments:
    The ESP DES-CBC Transform (RFC 1829) (19291 bytes)
    IP Encapsulating Security Payload (ESP) (RFC 1827) (30278 bytes) obsoleted by RFC 2406
    IP Authentication using Keyed MD5 (RFC 1828) (9800 bytes)
    IP Authentication Header (RFC 1826) (30475 bytes) obsoleted by RFC 2402
    Security Architecture for the Internet Protocol (RFC 1825) (56772 bytes) obsoleted by RFC 2401
    HMAC: Keyed-Hashing for Message Authentication (RFC 2104) (22297 bytes)
    HMAC-MD5 IP Authentication with Replay Prevention (RFC 2085) (13399 bytes)
    Security Architecture for the Internet Protocol (RFC 2401) (168162 bytes)
    The NULL Encryption Algorithm and Its Use With IPsec (RFC 2410) (11239 bytes)
    IP Security Document Roadmap (RFC 2411) (22796 bytes)
    IP Authentication Header (RFC 2402) (52831 bytes)
    The OAKLEY Key Determination Protocol (RFC 2412) (118649 bytes)
    The ESP CBC-Mode Cipher Algorithms (RFC 2451) (26400 bytes)
    The Use of HMAC-MD5-96 within ESP and AH (RFC 2403) (13578 bytes)
    The Use of HMAC-SHA-1-96 within ESP and AH (RFC 2404) (13089 bytes)
    The ESP DES-CBC Cipher Algorithm With Explicit IV (RFC 2405) (20208 bytes)
    IP Encapsulating Security Payload (ESP) (RFC 2406) (54202 bytes)
    The Internet IP Security Domain of Interpretation for ISAKMP (RFC 2407) (67878 bytes)
    Internet Security Association and Key Management Protocol (ISAKMP) (RFC 2408) (209194 bytes)
    The Internet Key Exchange (IKE) (RFC 2409) (94949 bytes)
    The Use of HMAC-RIPEMD-160-96 within ESP and AH (RFC 2857) (13544 bytes)
    More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) (RFC 3526) (19166 bytes)
    On the Use of Stream Control Transmission Protocol (SCTP) with IPsec (RFC 3554) (20102 bytes)

    Current Meeting Report

    None received.

    Slides

    None received.