[IPsec] Question about IKEv1 and ECDSA

2012-11-28 Thread Yoav Nir
Hi I know we don't like IKEv1 questions, but RFC 4754 does mention it, so here goes. And sorry if this has been discussed before. I couldn't find it. In IKEv1 the authentication method is negotiated as an SA parameter. So presumably the Initiator proposes RSA signatures, ECDSA with the P-256

Re: [IPsec] Question about IKEv1 and ECDSA

2012-11-28 Thread Paul Hoffman
On Nov 28, 2012, at 12:07 AM, Yoav Nir y...@checkpoint.com wrote: 1. Is it impossible to have one peer authenticate with RSA while the other authenticates with ECDSA, or even to mix curves? Or am I missing something? This was discussed a decade ago at interop events, and the general

[IPsec] AD VPN document

2012-11-28 Thread Yaron Sheffer
Hi everyone, Vishwas and Steve recently published version 01 of the Problem Statement ( http://tools.ietf.org/html/draft-ietf-ipsecme-ad-vpn-problem-01). We have already gone through WG last call on this one, so I would like to ask those who commented on the previous version to verify that