RFC 7427 · PROPOSED STANDARD · 2015

Signature Authentication in the Internet Key Exchange Version 2

Overview

RFC 7427, “Signature Authentication in the Internet Key Exchange Version 2”, is a Proposed Standard document published in January 2015 by T. Kivinen, J. Snyder. It updates RFC 7296. The canonical text is published by the RFC Editor.

Abstract

The Internet Key Exchange Version 2 (IKEv2) protocol has limited support for the Elliptic Curve Digital Signature Algorithm (ECDSA). The current version only includes support for three Elliptic Curve groups, and there is a fixed hash algorithm tied to each group. This document generalizes IKEv2 signature support to allow any signature method supported by PKIX and also adds signature hash algorithm negotiation. This is a generic mechanism and is not limited to ECDSA; it can also be used with other signature algorithms.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 7427 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC updates
RFC 7296
Other RFCs from 2015

Who Is Online

In total there are 69 users online: 0 registered, 65 guests and 4 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354