We have now finished our discussion about the IPsecME WG rechartering.

Here is the proposed new charter:
----------------------------------------------------------------------
The IPsec suite of protocols includes IKEv1 (RFC 2409 and associated
RFCs, IKEv1 is now obsoleted), IKEv2 (RFC 7296), the IPsec security
architecture (RFC 4301), AH (RFC 4302), and ESP (RFC 4303). IPsec is
widely deployed in VPN gateways, VPN remote access clients, and as a
substrate for host-to-host, host-to-network, and network-to-network
security.

The IPsec Maintenance and Extensions Working Group continues the work
of the earlier IPsec Working Group which was concluded in 2005. Its
purpose is to maintain the IPsec standard and to facilitate discussion
of clarifications, improvements, and extensions to IPsec, mostly to
ESP and IKEv2. The working group also serves as a focus point for
other IETF Working Groups who use IPsec in their own protocols.

The current work items include:

Postquantum Cryptography brings new authentication methods. The
working group will develop a solution, that allows adding Postquantum
authentication methods. The solution will allow post quantum
authentication methods to be performed in parallel with (or instead
of) the existing authentication methods. This work item may also
include solutions for transport issues because of larger payload and
message sizes.

The cryptographic algorithm implementation requirements and usage
guidance documents for IKEv2, ESP and AH was last time updated in
2017. The working group will work on the updating these documents.
This may also include defining how to use additional algorithms for
IPsec in separate documents (for example sha3, and including post
quantum algorithms).

There has been some need for tools making debugging IPsec
configurations easier, and the working group will work on documents to
help that. One such protocol could be esp-ping.

The ESPv3 protocol was defined in 2005 and there has been seen that
there might be some need to make enhancements to it. The working group
will analyze the possible problems and work on solving them. This may
include updating ESP, AH, and/or WESP standards, or result in a new
security protocol.
-- 
kivi...@iki.fi

_______________________________________________
IPsec mailing list -- ipsec@ietf.org
To unsubscribe send an email to ipsec-le...@ietf.org

Reply via email to