Guidelines for Specifying the Use of IPsec Version 2
RFC 5406, “Guidelines for Specifying the Use of IPsec Version 2”, is a Best Current Practice document published in February 2009 by S. Bellovin. The canonical text is published by the RFC Editor.
Abstract
The Security Considerations sections of many Internet Drafts say, in effect, "just use IPsec". While this is sometimes correct, more often it will leave users without real, interoperable security mechanisms. This memo offers some guidance on when IPsec Version 2 should and should not be specified. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.
What “Best Current Practice” means
Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.
The canonical text of RFC 5406 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5404 RTP Payload Format for G.719
- RFC 5408 Identity-Based Encryption Architecture and Supporting Data Structures
- RFC 5403 RPCSEC_GSS Version 2
- RFC 5409 Using the Boneh-Franklin and Boneh-Boyen Identity-Based Encryption Algorithms with the Cryptographic Message Syntax
- RFC 5410 Multimedia Internet KEYing General Extension Payload for Open Mobile Alliance BCAST 1.0
- RFC 5411 A Hitchhiker's Guide to the Session Initiation Protocol
- RFC 5415 Control And Provisioning of Wireless Access Points Protocol Specification
- RFC 5416 Control and Provisioning of Wireless Access Points Protocol Binding for IEEE 802.11