Passa al contenuto principale

8. References

8. To fix cryptographic weaknesses such as the problem with

 symmetries in hashes used for authentication (documented by Tero
Kivinen);

9. To specify Traffic Selectors in their own payloads type rather

 than overloading ID payloads, and making more flexible the
Traffic Selectors that may be specified;

10. To specify required behavior under certain error conditions or

 when data that is not understood is received in order to make it
easier to make future revisions in a way that does not break
backward compatibility;

Kaufman, et al. Standards Track [Page 132] RFC 5996 IKEv2bis September 2010

11. To simplify and clarify how shared state is maintained in the

 presence of network failures and DoS attacks; and

12. To maintain existing syntax and magic numbers to the extent

 possible to make it likely that implementations of IKEv1 can be
enhanced to support IKEv2 with minimum effort.