Re: [IPsec] Troubleshooting IPsec peer certs (was: Re: IPsec profile feedback wanted (draft autonomic control) plane)

2020-06-30 Thread Tero Kivinen
'Toerless Eckert' writes: > > And for some reason those same private enterprise/ISP people are > > exactly those who say that we can't leak our CA certificates out, and > > thats why we can't have publicly available repository of our > > certificates or CAs, which of course lead to problem if you m

Re: [IPsec] Troubleshooting IPsec peer certs (was: Re: IPsec profile feedback wanted (draft autonomic control) plane)

2020-06-30 Thread 'Toerless Eckert'
Thanks a lot, Tero for all your time responding, inline On Tue, Jun 30, 2020 at 10:26:26PM +0300, Tero Kivinen wrote: > I still consider sending TA certificate ever completely useless > thing, that just wastes bytes. Luckily it was not me alone who wanted that feature but it was triggered by Mic

[IPsec] RFC 8784 on Mixing Preshared Keys in the Internet Key Exchange Protocol Version 2 (IKEv2) for Post-quantum Security

2020-06-30 Thread rfc-editor
A new Request for Comments is now available in online RFC libraries. RFC 8784 Title: Mixing Preshared Keys in the Internet Key Exchange Protocol Version 2 (IKEv2) for Post-quantum Security Author: S. Fluhrer,