Requirements for an IPsec Certificate Management Profile
RFC 4809, “Requirements for an IPsec Certificate Management Profile”, is an Informational document published in February 2007 by C. Bonatti, S. Turner, G. Lebovitz. The canonical text is published by the RFC Editor.
Abstract
This informational document describes and identifies the requirements for transactions to handle Public Key Certificate (PKC) lifecycle transactions between Internet Protocol Security (IPsec) Virtual Private Network (VPN) Systems using Internet Key Exchange (IKE) (versions 1 and 2) and Public Key Infrastructure (PKI) Systems. These requirements are designed to meet the needs of enterprise-scale IPsec VPN deployments. It is intended that a standards track profile of a management protocol will be created to address many of these requirements. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 4809 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4808 Key Change Strategies for TCP-MD5
- RFC 4810 Long-Term Archive Service Requirements
- RFC 4807 IPsec Security Policy Database Configuration MIB
- RFC 4811 OSPF Out-of-Band Link State Database Resynchronization
- RFC 4806 Online Certificate Status Protocol Extensions to IKEv2
- RFC 4812 OSPF Restart Signaling
- RFC 4805 Definitions of Managed Objects for the DS1, J1, E1, DS2, and E2 Interface Types
- RFC 4813 OSPF Link-Local Signaling