RFC 4322 · INFORMATIONAL · 2005

Opportunistic Encryption using the Internet Key Exchange

Overview

RFC 4322, “Opportunistic Encryption using the Internet Key Exchange”, is an Informational document published in December 2005 by M. Richardson, D.H. Redelmeier. The canonical text is published by the RFC Editor.

Abstract

This document describes opportunistic encryption (OE) as designed and implemented by the Linux FreeS/WAN project. OE uses the Internet Key Exchange (IKE) and IPsec protocols. The objective is to allow encryption for secure communication without any pre-arrangement specific to the pair of systems involved. DNS is used to distribute the public keys of each system involved. This is resistant to passive attacks. The use of DNS Security (DNSSEC) secures this system against active attackers as well.

As a result, the administrative overhead is reduced from the square of the number of systems to a linear dependence, and it becomes possible to make secure communication the default even when the partner is not known in advance. This memo provides information for the Internet community.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 4322 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2005

Who Is Online

In total there are 100 users online: 0 registered, 90 guests and 10 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Googlebot Majestic Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372