RFC 5996 - Internet Key Exchange Protocol Version 2 (IKEv2, Internet-Schlüsselaustauschprotokoll Version 2)
- Status: Proposed Standard
- Veröffentlicht: September 2010
- Stream: IETF
- Ersetzt: RFC4306, RFC4718
- Ersetzt durch: RFC7296
- Errata: Keine Errata
Abstract (Zusammenfassung)
Dieses Dokument beschreibt Version 2 des Internet Key Exchange (IKE)-Protokolls. IKE ist eine Komponente von IPsec und wird zur gegenseitigen Authentifizierung sowie zum Aufbau und zur Pflege von Sicherheitsassoziationen (Security Associations, SAs) verwendet. Dieses Dokument ersetzt und aktualisiert RFC 4306 und übernimmt alle Klarstellungen aus RFC 4718.
Contents (Inhaltsverzeichnis)
- 1. Introduction (Einführung)
- 1.1. Usage Scenarios (Verwendungsszenarien)
- 1.1.1. Security Gateway to Security Gateway in Tunnel Mode (Sicherheitsgateway zu Sicherheitsgateway im Tunnelmodus)
- 1.1.2. Endpoint-to-Endpoint Transport Mode (Endpunkt-zu-Endpunkt-Transportmodus)
- 1.1.3. Endpoint to Security Gateway in Tunnel Mode (Endpunkt zu Sicherheitsgateway im Tunnelmodus)
- 1.1.4. Other Scenarios (Andere Szenarien)
- 1.2. The Initial Exchanges (Anfängliche Austausche)
- 1.3. The CREATE_CHILD_SA Exchange (CREATE_CHILD_SA-Austausch)
- 1.4. The INFORMATIONAL Exchange (INFORMATIONAL-Austausch)
- 1.5. Informational Messages outside of an IKE SA (Informationsmeldungen außerhalb einer IKE SA)
- 1.6. Requirements Terminology (Anforderungsterminologie)
- 1.7. Significant Differences from RFC 4306 (Wesentliche Unterschiede zu RFC 4306)
- 1.1. Usage Scenarios (Verwendungsszenarien)
- 2. IKE Protocol Details and Variations (IKE-Protokolldetails und -Varianten)
- 2.1. Use of Retransmission Timers (Verwendung von Retransmissions-Timern)
- 2.2. Use of Sequence Numbers for Message ID (Verwendung von Sequenznummern für die Nachrichten-ID)
- 2.3. Window Size for Overlapping Requests (Fenstergröße für überlappende Anfragen)
- 2.4. State Synchronization and Connection Timeouts (Zustandssynchronisation und Verbindungs-Timeouts)
- 2.5. Version Numbers and Forward Compatibility (Versionsnummern und Vorwärtskompatibilität)
- 2.6. IKE SA SPIs and Cookies (IKE-SA-SPIs und Cookies)
- 2.7. Cryptographic Algorithm Negotiation (Aushandlung kryptographischer Algorithmen)
- 2.8. Rekeying (Rekeying / Schlüsselerneuerung)
- 2.9. Traffic Selector Negotiation (Aushandlung von Traffic-Selektoren)
- 2.10. Nonces (Nonces)
- 2.11. Address and Port Agility (Adress- und Port-Agilität)
- 2.12. Reuse of Diffie-Hellman Exponentials (Wiederverwendung von Diffie-Hellman-Exponenten)
- 2.13. Generating Keying Material (Erzeugung von Schlüsselmaterial)
- 2.14. Generating Keying Material for the IKE SA (Erzeugung von Schlüsselmaterial für die IKE-SA)
- 2.15. Authentication of the IKE SA (Authentifizierung der IKE-SA)
- 2.16. Extensible Authentication Protocol Methods (Methoden des Extensible Authentication Protocol (EAP))
- 2.17. Generating Keying Material for Child SAs (Erzeugung von Schlüsselmaterial für Child-SAs)
- 2.18. Rekeying IKE SAs Using CREATE_CHILD_SA (Rekeying von IKE-SAs mit CREATE_CHILD_SA)
- 2.19. Requesting an Internal Address (Anfordern einer internen Adresse)
- 2.20. Requesting the Peer's Version (Abfragen der Version des Kommunikationspartners)
- 2.21. Error Handling (Fehlerbehandlung)
- 2.22. IPComp (IPComp)
- 2.23. NAT Traversal (NAT-Traversal)
- 2.24. Explicit Congestion Notification (Explicit Congestion Notification (ECN))
- 2.25. Exchange Collisions (Exchange-Kollisionen)
- 3. Header and Payload Formats (Header- und Payload-Formate)
- 3.1. The IKE Header (Der IKE-Header)
- 3.2. Generic Payload Header (Allgemeiner Payload-Header)
- 3.3. Security Association Payload (Security-Association-Payload)
- 3.4. Key Exchange Payload (Key-Exchange-Payload)
- 3.5. Identification Payloads (Identifikations-Payloads)
- 3.6. Certificate Payload (Zertifikat-Payload)
- 3.7. Certificate Request Payload (Zertifikatsanforderungs-Payload)
- 3.8. Authentication Payload (Authentifizierungs-Payload)
- 3.9. Nonce Payload (Nonce-Payload)
- 3.10. Notify Payload (Notify-Payload)
- 3.11. Delete Payload (Delete-Payload)
- 3.12. Vendor ID Payload (Vendor-ID-Payload)
- 3.13. Traffic Selector Payload (Traffic-Selektor-Payload)
- 3.14. Encrypted Payload (Verschlüsselter Payload)
- 3.15. Configuration Payload (Konfigurations-Payload)
- 3.16. Extensible Authentication Protocol Payload (Extensible-Authentication-Protocol-Payload (EAP))
- 4. Conformance Requirements (Konformitätsanforderungen)
- 5. Security Considerations (Sicherheitsüberlegungen)
- 6. IANA Considerations (IANA-Überlegungen)
- 7. Acknowledgements (Danksagungen)
- 8. References (Referenzen)
- Appendix A. Summary of Changes from IKEv1 (Anhang A. Zusammenfassung der Änderungen gegenüber IKEv1)
- Appendix B. Diffie-Hellman Groups (Anhang B. Diffie-Hellman-Gruppen)
- Appendix C. Exchanges and Payloads (Anhang C. Austausche und Payloads)
Copyright Notice (Urheberrechtshinweis)
Copyright (c) 2010 IETF Trust und die als Dokumentautoren identifizierten Personen. Alle Rechte vorbehalten.
Dieses Dokument unterliegt BCP 78 und den rechtlichen Bestimmungen des IETF Trust in Bezug auf IETF-Dokumente (http://trustee.ietf.org/license-info), die zum Zeitpunkt der Veröffentlichung dieses Dokuments in Kraft sind. Bitte lesen Sie diese Dokumente sorgfältig durch, da sie Ihre Rechte und Einschränkungen in Bezug auf dieses Dokument beschreiben.