The NULL Authentication Method in the Internet Key Exchange Protocol Version 2
RFC 7619, “The NULL Authentication Method in the Internet Key Exchange Protocol Version 2”, is a Proposed Standard document published in August 2015 by V. Smyslov, P. Wouters. It updates RFC 4301. The canonical text is published by the RFC Editor.
Abstract
This document specifies the NULL Authentication method and the ID_NULL Identification Payload ID Type for Internet Key Exchange Protocol version 2 (IKEv2). This allows two IKE peers to establish single-side authenticated or mutual unauthenticated IKE sessions for those use cases where a peer is unwilling or unable to authenticate or identify itself. This ensures IKEv2 can be used for Opportunistic Security (also known as Opportunistic Encryption) to defend against Pervasive Monitoring attacks without the need to sacrifice anonymity.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7619 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7618 Dynamic Allocation of Shared IPv4 Addresses
- RFC 7620 Scenarios with Host Identification Complications
- RFC 7617 The 'Basic' HTTP Authentication Scheme
- RFC 7621 A Clarification on the Use of Globally Routable User Agent URIs in the SIP Event Notification Framework
- RFC 7616 HTTP Digest Access Authentication
- RFC 7622 Extensible Messaging and Presence Protocol : Address Format
- RFC 7615 HTTP Authentication-Info and Proxy-Authentication-Info Response Header Fields
- RFC 7623 Provider Backbone Bridging Combined with Ethernet VPN