Repeated Authentication in Internet Key Exchange Protocol
RFC 4478, “Repeated Authentication in Internet Key Exchange Protocol”, is an Experimental document published in April 2006 by Y. Nir. The canonical text is published by the RFC Editor.
Abstract
This document extends the Internet Key Exchange (IKEv2) Protocol document [IKEv2]. With some IPsec peers, particularly in the remote access scenario, it is desirable to repeat the mutual authentication periodically. The purpose of this is to limit the time that security associations (SAs) can be used by a third party who has gained control of the IPsec peer. This document describes a mechanism to perform this function. This memo defines an Experimental Protocol for the Internet community.
What “Experimental” means
Describes a specification that is part of a research or development effort, published so the community can gain experience with it.
The canonical text of RFC 4478 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4477 Dynamic Host Configuration Protocol : IPv4 and IPv6 Dual-Stack Issues
- RFC 4479 A Data Model for Presence
- RFC 4476 Attribute Certificate Policies Extension
- RFC 4480 RPID: Rich Presence Extensions to the Presence Information Data Format
- RFC 4475 Session Initiation Protocol Torture Test Messages
- RFC 4481 Timed Presence Extensions to the Presence Information Data Format to Indicate Status Information for Past and Future Time Intervals
- RFC 4474 Enhancements for Authenticated Identity Management in the Session Initiation Protocol
- RFC 4482 CIPID: Contact Information for the Presence Information Data Format