RFC 7321: Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 8221.
Current document in this lineage: RFC 4302 — IP Authentication Header; RFC 4303 — IP Encapsulating Security Payload (ESP); RFC 8221 — Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)
In plain English — editorial summary, not part of the RFC
This document updates the Cryptographic Algorithm Implementation Requirements for the Encapsulating Security Payload (ESP) and Authentication Header (AH). It also adds usage guidance to help in the selection of these algorithms. ESP and AH protocols make use of various cryptographic algorithms to provide confidentiality and/or data origin authentication to protected data communications in the IP Security (IPsec) architecture. To ensure interoperability between disparate implementations, the IPsec standard specifies a set of mandatory-to- implement algorithms. This document specifies the current set of mandatory-to-implement algorithms for ESP and AH, specifies algorithms that should be implemented because they may be promoted to mandatory at some future time, and also recommends against the implementation of some obsolete algorithms. Usage guidance is also provided to help the user of ESP and AH best achieve their security goals through appropriate choices of cryptographic algorithms.
Document record
- Document ID
- RFC7321
- Published
- August 2014
- Authors
- D. McGrew; P. Hoffman
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 11
- Also known as
- —
Standards lineage
This document is one revision in a chain of 10 RFCs, each formally replacing the one before it.
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7301Transport Layer Security (TLS) Application-Layer Protocol Negotiation ExtensionUpdated
July 2014
- RFC 7296Internet Key Exchange Protocol Version 2 (IKEv2)Updated
October 2014
- RFC 7360Datagram Transport Layer Security (DTLS) as a Transport Layer for RADIUSUpdated
September 2014
- RFC 7366Encrypt-then-MAC for Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)Current
September 2014
- RFC 7268RADIUS Attributes for IEEE 802 NetworksUpdated
July 2014
- RFC 7383Internet Key Exchange Protocol Version 2 (IKEv2) Message FragmentationCurrent
November 2014
- RFC 7250Using Raw Public Keys in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)Current
June 2014
- RFC 7218Adding Acronyms to Simplify Conversations about DNS-Based Authentication of Named Entities (DANE)Current
April 2014
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?