CurrentPROPOSED STANDARDIETF stream

RFC 7427: Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)

In plain English — editorial summary, not part of the RFC

The Internet Key Exchange Version 2 (IKEv2) protocol has limited support for the Elliptic Curve Digital Signature Algorithm (ECDSA). The current version only includes support for three Elliptic Curve groups, and there is a fixed hash algorithm tied to each group. This document generalizes IKEv2 signature support to allow any signature method supported by PKIX and also adds signature hash algorithm negotiation. This is a generic mechanism and is not limited to ECDSA; it can also be used with other signature algorithms.

Document record

Document ID
RFC7427
Published
January 2015
Authors
T. Kivinen; J. Snyder
Status
PROPOSED STANDARD
Stream
IETF
Area
sec
Pages
18
Also known as
Updates:
RFC 7296

Topics

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/7427-signature-authentication-in-the-internet-key-exchange-version-2-ikev2