[anonsec] details of IKE/IPsec channel binding
Nicolas Williams
Nicolas.Williams at sun.com
Fri Mar 23 02:23:27 PDT 2007
On Thu, Mar 22, 2007 at 09:38:39AM -0400, Stephen Kent wrote:
> >IKEv1 is certainly not obsoleted. And RFC4301 does support IKEv1, does
> >it not?
>
> 4301 includes mandatory features that IKEv1 cannot negotiate, so in
> that sense 4301 assumes use of IKEv2.
But if we can write connection latching and channel binding specs in a
sufficiently neutral way that IKEv1/RFC2401 can be used, wouldn't that
be good? I did try to write the connection latching I-D that way.
Nico
--
More information about the ANONSEC
mailing list