Cryptographic Algorithm Implementation Requirements for Encapsulating Security Payload and Authentication Header
RFC 4305, “Cryptographic Algorithm Implementation Requirements for Encapsulating Security Payload and Authentication Header”, is a Proposed Standard document published in December 2005 by D. Eastlake 3rd. It obsoletes RFC 2402, RFC 2406. It has been obsoleted by RFC 4835 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
The IPsec series of protocols makes use of various cryptographic algorithms in order to provide security services. The Encapsulating Security Payload (ESP) and the Authentication Header (AH) provide two mechanisms for protecting data being sent over an IPsec Security Association (SA). To ensure interoperability between disparate implementations, it is necessary to specify a set of mandatory-to-implement algorithms to ensure that there is at least one algorithm that all implementations will have available. This document defines the current set of mandatory-to-implement algorithms for ESP and AH as well as specifying algorithms that should be implemented because they may be promoted to mandatory at some future time. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 4305 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4304 Extended Sequence Number Addendum to IPsec Domain of Interpretation for Internet Security Association and Key Management Protocol
- RFC 4306 Internet Key Exchange Protocol
- RFC 4303 IP Encapsulating Security Payload
- RFC 4307 Cryptographic Algorithms for Use in the Internet Key Exchange Version 2
- RFC 4302 IP Authentication Header
- RFC 4308 Cryptographic Suites for IPsec
- RFC 4301 Security Architecture for the Internet Protocol
- RFC 4309 Using Advanced Encryption Standard CCM Mode with IPsec Encapsulating Security Payload