<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.williams-btns-unauthenticated-bits" target="https://datatracker.ietf.org/doc/html/draft-williams-btns-unauthenticated-bits-00">
   <front>
      <title>An Unauthenticated, or Leap-of-Faith-Authorization Mode for Bump-In-The-Stack Implementations of IPsec Using Internet Key Exchange Protocols</title>
      <author initials="N." surname="Williams" fullname="Nicolás Williams">
         <organization>Sun</organization>
      </author>
      <date month="May" day="2" year="2005" />
      <abstract>
	 <t>   This document specifies how to use the Internet Key Exchange (IKE)
   protocols, such as IKEv1 and IKEv2, to setup &quot;unauthenticated&quot;
   security associations (SAs) using public keys as IKE identities and
   unauthenticated public keys and/or certificates as IKE credentials.
   This unauthenticated SA negotiation protocol works by having IKE
   peers assert public keys as identities using a new IKE ID payload
   type for the purpose.  Unauthenticated IPsec is herein referred to by
   its popular acronym, &quot;BTNS&quot; (Better Than Nothing Security).

   This document focuses on BITS (bump in the stack) mode IPsec, leaving
   specification of unauthenticated native IPsec to a separate document.
   We assume an RFC2401bis processing model, specifically a PAD (peer
   authorization database) separate from the SPD (security policy
   database).
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-williams-btns-unauthenticated-bits-00" />
   
</reference>
