RFC 8247: Algorithm Implementation Requirements and Usage Guidance for the Internet Key Exchange Protocol Version 2 (IKEv2)
In plain English — editorial summary, not part of the RFC
The IPsec series of protocols makes use of various cryptographic algorithms in order to provide security services. The Internet Key Exchange (IKE) protocol is used to negotiate the IPsec Security Association (IPsec SA) parameters, such as which algorithms should be used. To ensure interoperability between different implementations, it is necessary to specify a set of algorithm implementation requirements and usage guidance to ensure that there is at least one algorithm that all implementations support. This document updates RFC 7296 and obsoletes RFC 4307 in defining the current algorithm implementation requirements and usage guidance for IKEv2, and does minor cleaning up of the IKEv2 IANA registry. This document does not update the algorithms used for packet encryption using IPsec Encapsulating Security Payload (ESP).
Document record
- Document ID
- RFC8247
- Published
- September 2017
- Authors
- Y. Nir; T. Kivinen; P. Wouters; D. Migault
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 19
- Also known as
- —
Topics
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4301Security Architecture for the Internet ProtocolUpdated
December 2005
- RFC 4303IP Encapsulating Security Payload (ESP)Current
December 2005
- RFC 4302IP Authentication HeaderCurrent
December 2005
- RFC 8229TCP Encapsulation of IKE and IPsec PacketsObsoleted
August 2017
- RFC 8221Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)Updated
October 2017
- RFC 8750Implicit Initialization Vector (IV) for Counter-Based Ciphers in Encapsulating Security Payload (ESP)Current
March 2020
- RFC 7634ChaCha20, Poly1305, and Their Use in the Internet Key Exchange Protocol (IKE) and IPsecCurrent
August 2015
- RFC 7427Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)Current
January 2015
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?