[IPsec] IKEv2 PFS, IKE Rekey KE Payload

2015-08-25 Thread riyaz talikoti
Hi All, I have a basic doubt with IKEv2, IKE SA rekey with PFS configured. Sorry for the broadcast mail. I have configured as below IKE proposal DH Group 14 IPSEC Proposal PFS DH Group 2 During INIT EXCHANGE DH Group 14 will be used to calculate KE payload value. and For IPSEC SA's (CHILD SA

Re: [IPsec] IKEv2 PFS, IKE Rekey KE Payload

2015-08-25 Thread Paul Wouters
On Tue, 25 Aug 2015, riyaz talikoti wrote: I have a basic doubt with IKEv2, IKE SA rekey with PFS configured. I have configured as below IKE proposal DH Group 14 IPSEC Proposal PFS DH Group 2 During INIT EXCHANGE DH Group 14 will be used to calculate KE payload value. and For IPSEC SA's

Re: [IPsec] My review of draft-nir-ipsecme-curve25519

2015-08-25 Thread Yoav Nir
On Aug 25, 2015, at 3:19 PM, Tero Kivinen kivi...@iki.fi wrote: Firstly the name of the draft is bit misleading, as this defines both curve25519 and Curve448 keys not only curve25519. Agree. Version -00 had only Curve25519 and the name remained. For the WG draft we can pick a different

[IPsec] Call for adoption: draft-nir-ipsecme-curve25519 as a WG work item

2015-08-25 Thread Tero Kivinen
Paul Hoffman writes: Greetings. There was some general interest in having a standard way to modern elliptic curves for ephemeral key exchange. Please respond in this thread whether or no you think this document is a good start on that work, and whether or not you think the WG should have