Opportunistic Encryption using the Internet Key Exchange
RFC 4322, “Opportunistic Encryption using the Internet Key Exchange”, is an Informational document published in December 2005 by M. Richardson, D.H. Redelmeier. The canonical text is published by the RFC Editor.
Abstract
This document describes opportunistic encryption (OE) as designed and implemented by the Linux FreeS/WAN project. OE uses the Internet Key Exchange (IKE) and IPsec protocols. The objective is to allow encryption for secure communication without any pre-arrangement specific to the pair of systems involved. DNS is used to distribute the public keys of each system involved. This is resistant to passive attacks. The use of DNS Security (DNSSEC) secures this system against active attackers as well.
As a result, the administrative overhead is reduced from the square of the number of systems to a linear dependence, and it becomes possible to make secure communication the default even when the partner is not known in advance. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 4322 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4324 Calendar Access Protocol
- RFC 4319 Definitions of Managed Objects for High Bit-Rate DSL - 2nd generation and Single-Pair High-Speed Digital Subscriber Line Lines
- RFC 4325 Internet X.509 Public Key Infrastructure Authority Information Access Certificate Revocation List Extension
- RFC 4318 Definitions of Managed Objects for Bridges with Rapid Spanning Tree Protocol
- RFC 4326 Unidirectional Lightweight Encapsulation for Transmission of IP Datagrams over an MPEG-2 Transport Stream
- RFC 4317 Session Description Protocol Offer/Answer Examples
- RFC 4316 Datatypes for Web Distributed Authoring and Versioning Properties
- RFC 4315 Internet Message Access Protocol - UIDPLUS extension