1 / 5

The Internet IP Security PKI Profile of ISAKMP and PKIX

The Internet IP Security PKI Profile of ISAKMP and PKIX. draft-ietf-ipsec-pki-profile-01.txt Brian Korver <briank@xythos.com> Eric Rescorla <ekr@rtfm.com>. What is draft-ietf-ipsec-pki-profile-01.txt?. Provides a profile of ISAKMP and PKIX for use in IPsec

bwang
Download Presentation

The Internet IP Security PKI Profile of ISAKMP and PKIX

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. The Internet IP Security PKI Profile of ISAKMP and PKIX draft-ietf-ipsec-pki-profile-01.txt Brian Korver <briank@xythos.com> Eric Rescorla <ekr@rtfm.com>

  2. What isdraft-ietf-ipsec-pki-profile-01.txt? • Provides a profile of ISAKMP and PKIX for use in IPsec • Complements specifications such as IKEv1 and IKE v2 • -00 and -01 are “strawman” proposals

  3. Examples of issues addressed in draft-ietf-ipsec-pki-profile-01.txt • When should an implementation send Certificates and/or CRLs? • What response should be given to an empty CERTREQ? • How must the ID payload be used for determining policy? • In which fields should particular types of identity information appear in certificates? • What formats should be used for out-of-band exchange of PKI-related information?

  4. What’s new in -01? • Reformatted • Incorporation of some comments

  5. Going forward to -02 • Send feedback to the list at ipsec@lists.tislabs.com • Hopefully -02 will be better than just a “strawman”

More Related