Hi Tirumal Excellent.
Thank you and yes that addresses my concern. I believe this draft is ready for publication. Kind Regards Gyan On Fri, Jul 24, 2026 at 3:46 AM tirumal reddy <[email protected]> wrote: > Hi Gyan, > > Thanks for the review. No new IKEv2 code points are needed. The draft > reuses the generic Digital Signature method (RFC 7427), which identifies > the algorithm by OID in the AUTH payload, so new PQC algorithms need no > IKEv2 registry change. > Rekeying is unaffected by the PQC signature algorithms, CREATE_CHILD_SA > carries no AUTH payload. > > Cheers, > -Tiru > > On Mon, 20 Jul 2026 at 02:40, Gyan Mishra via Datatracker < > [email protected]> wrote: > >> Document: draft-ietf-ipsecme-ikev2-pqc-auth >> Title: Signature Authentication in the Internet Key Exchange Version 2 >> (IKEv2) >> using PQC Reviewer: Gyan Mishra Review result: Almost Ready >> >> I am the assigned Gen-ART reviewer for this draft. The General Area >> Review Team (Gen-ART) reviews all IETF documents being processed >> by the IESG for the IETF Chair. Please treat these comments just >> like any other last call comments. >> >> For more information, please see the FAQ at >> >> <https://wiki.ietf.org/en/group/gen/GenArtFAQ>. >> >> Document: draft-ietf-ipsecme-ikev2-pqc-auth-?? >> Reviewer: Gyan Mishra >> Review Date: 2026-07-19 >> IETF LC End Date: 2026-07-31 >> IESG Telechat date: Not scheduled for a telechat >> >> Summary: >> >> Signature-based authentication methods are utilized in the Internet Key >> Exchange Version 2 (IKEv2). The current version of the IKEv2 protocol, >> specified in RFC 7296, supports traditional digital signatures. >> >> This document specifies a generic mechanism for integrating post-quantum >> cryptographic (PQC) digital signature algorithms into the IKEv2 protocol. >> The >> approach allows for seamless inclusion of any PQC signature scheme within >> the >> existing authentication framework of IKEv2. Additionally, it outlines how >> Module-Lattice-Based Digital Signatures (ML-DSA) and Stateless Hash-Based >> Digital Signatures (SLH-DSA), can be employed as authentication methods >> within >> the IKEv2 protocol, as they have been standardized by US NIST. >> >> I believe this specification is almost ready for publication. >> >> One question I would like to ask the authors is related to any IANA code >> points >> for the use of PQC for signature for IKEv2. >> >> As this is standards track and a significant change to IKEv2 which does >> impact >> all IPSEC implementations vendors supporting the PQM update feature. >> >> To ensure standardization and forward and backward compatibility in the >> implementation should there be a standard codepoint allocated for the >> drafts >> update to IKEv2 for PQM signature signing. >> >> What is the impact on SA security association rekeying during key update >> intervals. I do not see anything mentioned related but as we are using a >> new >> PQM signing mechanism, I wonder if there is any impact and if so it >> should be >> added to the considerations section. >> >> Major issues: >> None >> >> Minor issues: >> None >> >> Nits/editorial comments: >> None >> >> >>
_______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
