Name: draft-richardson-ipsec-opportunistic-16
Title: Opportunistic Encryption using The Internet Key Exchange (IKE)
State: Pending
Authors: Michael Richardson, D. Hugh Redelmeier
Group: Individual Submissions (none)
Date: 2004-07-19
This document describes opportunistic encryption (OE) as designed and
implemented by the Linux FreeS/WAN project. OE uses the Internet Key
Exchange (IKE) and IPsec protocols. The objective is to allow encryption
for secure communication without any pre-arrangement specific to the pair
of systems involved. DNS is used to distribute the public keys of each
system involved. This is resistant to passive attacks. The use of DNS
Security (DNSSEC) secures this system against active attackers as well.
|
|
|