Online Certificate Status Protocol Extensions to IKEv2
RFC 4806, “Online Certificate Status Protocol Extensions to IKEv2”, is a Proposed Standard document published in February 2007 by M. Myers, H. Tschofenig. The canonical text is published by the RFC Editor.
Abstract
While the Internet Key Exchange Protocol version 2 (IKEv2) supports public key based authentication, the corresponding use of in-band Certificate Revocation Lists (CRL) is problematic due to unbounded CRL size. The size of an Online Certificate Status Protocol (OCSP) response is however well-bounded and small. This document defines the "OCSP Content" extension to IKEv2. A CERTREQ payload with "OCSP Content" identifies zero or more trusted OCSP responders and is a request for inclusion of an OCSP response in the IKEv2 handshake. A cooperative recipient of such a request responds with a CERT payload containing the appropriate OCSP response. This content is recognizable via the same "OCSP Content" identifier.
When certificates are used with IKEv2, the communicating peers need a mechanism to determine the revocation status of the peer's certificate. OCSP is one such mechanism. This document applies when OCSP is desired and security policy prevents one of the IKEv2 peers from accessing the relevant OCSP responder directly. Firewalls are often deployed in a manner that prevents such access by IKEv2 peers outside of an enterprise network. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 4806 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4805 Definitions of Managed Objects for the DS1, J1, E1, DS2, and E2 Interface Types
- RFC 4807 IPsec Security Policy Database Configuration MIB
- RFC 4804 Aggregation of Resource ReSerVation Protocol Reservations over MPLS TE/DS-TE Tunnels
- RFC 4808 Key Change Strategies for TCP-MD5
- RFC 4803 Generalized Multiprotocol Label Switching Label Switching Router Management Information Base
- RFC 4809 Requirements for an IPsec Certificate Management Profile
- RFC 4802 Generalized Multiprotocol Label Switching Traffic Engineering Management Information Base
- RFC 4810 Long-Term Archive Service Requirements