Multiple Authentication Exchanges in the Internet Key Exchange Protocol
RFC 4739, “Multiple Authentication Exchanges in the Internet Key Exchange Protocol”, is an Experimental document published in November 2006 by P. Eronen, J. Korhonen. The canonical text is published by the RFC Editor.
Abstract
The Internet Key Exchange (IKEv2) protocol supports several mechanisms for authenticating the parties, including signatures with public-key certificates, shared secrets, and Extensible Authentication Protocol (EAP) methods. Currently, each endpoint uses only one of these mechanisms to authenticate itself. This document specifies an extension to IKEv2 that allows the use of multiple authentication exchanges, using either different mechanisms or the same mechanism. This extension allows, for instance, performing certificate-based authentication of the client host followed by an EAP authentication of the user. When backend authentication servers are used, they can belong to different administrative domains, such as the network access provider and the service provider. This memo defines an Experimental Protocol for the Internet community.
What “Experimental” means
Describes a specification that is part of a research or development effort, published so the community can gain experience with it.
The canonical text of RFC 4739 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4738 MIKEY-RSA-R: An Additional Mode of Key Distribution in Multimedia Internet KEYing
- RFC 4740 Diameter Session Initiation Protocol Application
- RFC 4737 Packet Reordering Metrics
- RFC 4741 NETCONF Configuration Protocol
- RFC 4736 Reoptimization of Multiprotocol Label Switching Traffic Engineering Loosely Routed Label Switched Path
- RFC 4742 Using the NETCONF Configuration Protocol over Secure SHell
- RFC 4735 Example Media Types for Use in Documentation
- RFC 4743 Using NETCONF over the Simple Object Access Protocol