{
  "number": 7427,
  "title": "Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)",
  "authors": [
    "T. Kivinen",
    "J. Snyder"
  ],
  "published": "2015-01",
  "status": "Proposed Standard",
  "stream": "IETF",
  "area": "sec",
  "working_group": "ipsecme",
  "pages": 18,
  "formats": [
    "TXT",
    "HTML"
  ],
  "abstract": "The Internet Key Exchange Version 2 (IKEv2) protocol has limited support for the Elliptic Curve Digital Signature Algorithm (ECDSA). The current version only includes support for three Elliptic Curve groups, and there is a fixed hash algorithm tied to each group. This document generalizes IKEv2 signature support to allow any signature method supported by PKIX and also adds signature hash algorithm negotiation. This is a generic mechanism and is not limited to ECDSA; it can also be used with other signature algorithms.",
  "keywords": [
    "IPsec",
    "IKE",
    "IKEv2",
    "Signature",
    "Authentication",
    "RSA",
    "DSS",
    "DSA",
    "ECDSA",
    "SASSA-PSS",
    "PKIX"
  ],
  "draft": "draft-kivinen-ipsecme-signature-auth-07",
  "doi": "10.17487/RFC7427",
  "updates": [
    "RFC7296"
  ],
  "urls": {
    "html": "https://rfc.dk/rfc7427/",
    "text": "https://rfc.dk/rfc7427.txt",
    "rfc_editor": "https://www.rfc-editor.org/rfc/rfc7427",
    "datatracker": "https://datatracker.ietf.org/doc/rfc7427/"
  },
  "text_modified": "2015-01-07T01:42:56Z"
}
