IPsec Channels: Connection Latching | |||||||||||||||||
|
This document specifies, abstractly, how to interface applications and transport protocols with IPsec so as to create "channels" by latching "connections" (packet flows) to certain IPsec Security Association (SA) parameters for the lifetime of the connections. Connection latching is layered on top of IPsec and does not modify the underlying IPsec architecture. Connection latching can be used to protect applications against accidentally exposing live packet flows to unintended peers, whether as the result of a reconfiguration of IPsec or as the result of using weak peer identity to peer address associations. Weak association of peer ID and peer addresses is at the core of Better Than Nothing Security (BTNS), thus connection latching can add a significant measure of protection to BTNS IPsec nodes. Finally, the availability of IPsec channels will make it possible to use channel binding to IPsec channels. |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Last Modified: 2009-02-11
Additional information is available at tools.ietf.org/wg/btns
Done | Confirm on mailing list whether SPD and/or PAD extensions are needed (d) | |
Done | First version of problem and applicability statement (a+b) | |
Done | First version of SPD and/or PAD extensions draft (if needed) | |
Done | First version of IKE extensions draft (if needed) | |
Done | WG LC on problem and applicability statement (a+b) | |
Done | Submit problem and applicability statement to IESG (a+b) | |
Done | First version of IPsec interfaces draft (e) | |
Feb 2007 | WG LC on IKE extensions (c) | |
Done | WG LC on SPD and/or PAD extensions (d) | |
Mar 2007 | Submit IKE extensions to the IESG | |
Done | Submit SPD and/or PAD extensions to the IESG | |
Oct 2007 | WG LC on IPsec interfaces draft | |
Nov 2007 | Submit IPsec interfaces draft to the IESG | |
Nov 2007 | Recharter or close the WG |