[anonsec] details of IKE/IPsec channel binding

Nicolas Williams Nicolas.Williams at sun.com
Fri Mar 23 02:23:27 PDT 2007


On Thu, Mar 22, 2007 at 09:38:39AM -0400, Stephen Kent wrote:
> >IKEv1 is certainly not obsoleted.  And RFC4301 does support IKEv1, does
> >it not?
> 
> 4301 includes mandatory features that IKEv1 cannot negotiate, so in 
> that sense 4301 assumes use of IKEv2.

But if we can write connection latching and channel binding specs in a
sufficiently neutral way that IKEv1/RFC2401 can be used, wouldn't that
be good?  I did try to write the connection latching I-D that way.

Nico
-- 


More information about the ANONSEC mailing list