RFC 4322: Opportunistic Encryption using the Internet Key Exchange (IKE)
In plain English — editorial summary, not part of the RFC
This document describes opportunistic encryption (OE) as designed and implemented by the Linux FreeS/WAN project. OE uses the Internet Key Exchange (IKE) and IPsec protocols. The objective is to allow encryption for secure communication without any pre-arrangement specific to the pair of systems involved. DNS is used to distribute the public keys of each system involved. This is resistant to passive attacks. The use of DNS Security (DNSSEC) secures this system against active attackers as well. As a result, the administrative overhead is reduced from the square of the number of systems to a linear dependence, and it becomes possible to make secure communication the default even when the partner is not known in advance. This memo provides information for the Internet community.
Document record
- Document ID
- RFC4322
- Published
- December 2005
- Authors
- M. Richardson; D.H. Redelmeier
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- —
- Pages
- 44
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4301Security Architecture for the Internet ProtocolUpdated
December 2005
- RFC 4431The DNSSEC Lookaside Validation (DLV) DNS Resource RecordCurrent
February 2006
- RFC 4641DNSSEC Operational PracticesObsoleted
September 2006
- RFC 3845DNS Security (DNSSEC) NextSECure (NSEC) RDATA FormatObsoleted
August 2004
- RFC 3755Legacy Resolver Compatibility for Delegation Signer (DS)Obsoleted
May 2004
- RFC 2401Security Architecture for the Internet ProtocolObsoleted
November 1998
- RFC 4307Cryptographic Algorithms for Use in the Internet Key Exchange Version 2 (IKEv2)Obsoleted
December 2005
- RFC 4306Internet Key Exchange (IKEv2) ProtocolObsoleted
December 2005
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?