Skip to main content

Commercial National Security Algorithm (CNSA) Suite Cryptography for Internet Protocol Security (IPsec)
draft-corcoran-cnsa-ipsec-profile-06

Revision differences

Document history

Date Rev. By Action
2022-02-28
06 (System)
Received changes through RFC Editor sync (created alias RFC 9206, changed abstract to 'The United States Government has published the National Security Agency's Commercial …
Received changes through RFC Editor sync (created alias RFC 9206, changed abstract to 'The United States Government has published the National Security Agency's Commercial National Security Algorithm (CNSA) Suite, which defines cryptographic algorithm policy for national security applications.  This document specifies the conventions for using the United States National Security Agency's CNSA Suite algorithms in Internet Protocol Security (IPsec).  It applies to the capabilities, configuration, and operation of all components of US National Security Systems (described in NIST Special Publication 800-59) that employ IPsec.  This document is also appropriate for all other US Government systems that process high-value information.  It is made publicly available for use by developers and operators of these and any other system deployments.', changed pages to 13, changed standardization level to Informational, changed state to RFC, added RFC published event at 2022-03-01, changed ISE state to Published RFC)
2022-02-24
06 (System) RFC Editor state changed to AUTH48-DONE from AUTH48
2022-02-17
06 (System) RFC Editor state changed to AUTH48
2022-01-26
06 (System) IANA Action state changed to RFC-Ed-Ack from Waiting on RFC Editor
2022-01-26
06 (System) RFC Editor state changed to RFC-EDITOR from IANA
2022-01-26
06 (System) IANA Action state changed to Waiting on RFC Editor from In Progress
2022-01-26
06 (System) IANA Action state changed to In Progress from Waiting on Authors
2022-01-25
06 (System) IANA Action state changed to Waiting on Authors from In Progress
2022-01-25
06 (System) IANA Action state changed to In Progress from On Hold
2022-01-24
06 (System) RFC Editor state changed to IANA from EDIT
2022-01-14
06 (System) IANA Action state changed to On Hold from In Progress
2022-01-12
06 (System) RFC Editor state changed to EDIT
2022-01-12
06 (System) IANA Action state changed to In Progress
2022-01-12
06 Adrian Farrel ISE state changed to Sent to the RFC Editor from In IESG Review
2022-01-12
06 Adrian Farrel Sent request for publication to the RFC Editor
2022-01-11
06 (System) IANA Review state changed to Version Changed - Review Needed from IANA OK - Actions Needed
2022-01-11
06 Michael Jenkins New version available: draft-corcoran-cnsa-ipsec-profile-06.txt
2022-01-11
06 (System) New version approved
2022-01-11
06 (System) Request for posting confirmation emailed to previous authors: Laura Corcoran , Michael Jenkins
2022-01-11
06 Michael Jenkins Uploaded new revision
2022-01-03
05 Amanda Baber
(Via drafts-eval@iana.org): IESG/Authors/ISE:

The IANA Functions Operator has completed its review of draft-corcoran-cnsa-ipsec-profile-05. If any part of this review is inaccurate, please let us …
(Via drafts-eval@iana.org): IESG/Authors/ISE:

The IANA Functions Operator has completed its review of draft-corcoran-cnsa-ipsec-profile-05. If any part of this review is inaccurate, please let us know.

We understand that when this document is sent to us for processing, we will perform one registry action.

The following entries will be added to the Cryptographic Suites for IKEv1, IKEv2, and IPsec registry at

https://www.iana.org/assignments/crypto-suites

        +-----------------------+--------------------------------+
        |      Identifier      |          Reference            |
        +-----------------------+--------------------------------+
        | CNSA-GCM-256-ECDH-384 | [this document when published] |
        +-----------------------+--------------------------------+
        | CNSA-GCM-256-DH-3072  | [this document when published] |
        +-----------------------+--------------------------------+
        | CNSA-GCM-256-DH-4096  | [this document when published] |
        +-----------------------+--------------------------------+

These registrations have already been approved by the designated expert.

Thank you,

Amanda
IANA Services Specialist
2022-01-03
05 Amanda Baber IANA Review state changed to IANA OK - Actions Needed
2022-01-03
05 Amanda Baber IANA Experts State changed to Expert Reviews OK
2021-12-17
05 (System) Revised ID Needed tag cleared
2021-12-17
05 Michael Jenkins New version available: draft-corcoran-cnsa-ipsec-profile-05.txt
2021-12-17
05 (System) New version approved
2021-12-17
05 (System) Request for posting confirmation emailed to previous authors: Laura Corcoran , Michael Jenkins
2021-12-17
05 Michael Jenkins Uploaded new revision
2021-12-16
04 Adrian Farrel Tag Revised I-D Needed set.
2021-12-16
04 Adrian Farrel ISE state changed to In IESG Review from In ISE Review
2021-12-16
04 Adrian Farrel IETF conflict review initiated - see conflict-review-corcoran-cnsa-ipsec-profile
2021-12-16
04 Adrian Farrel
draft-corcoran-cnsa-ipsec-profile has been presented to the ISE for
publication as an Informational RFC on the Independent Stream.

==Purpose==

This document forms one of a series …
draft-corcoran-cnsa-ipsec-profile has been presented to the ISE for
publication as an Informational RFC on the Independent Stream.

==Purpose==

This document forms one of a series that set out the US Government's
Commercial National Security Algorithm (CNSA) Suite.  This document
specifies the conventions for using the CNSA Suite algorithms in
Internet Protocol Security.  It applies specifically to IPsec.

The series of documents are made publicly available through the RFC
Series for use by developers and operators of these and any other
system deployments.

== History==

This document has seen no discussion within the IETF.

The document was first brought to the ISE in December 2019 at version
-00. Since then it has been revised several times to address review
comments.

==Non-IETF Work==

The document title, the Abstract, and the Introduction make the scope
of this work clear. There is no risk of confusing this for IETF work.

==Security Considerations==

The whole document is relevant to Security. Nevertheless, the authors
have also provided a Security Considerations section to highlight some
additional points.

==IANA==

This document requests IANA to make assignments from the registry at
https://www.iana.org/assignments/crypto-suites
The assignment policy for that registry is "Expert Review and RFC
Required"

The Designated Expert for the registry is Tero Kivinen. Tero provided
a positive opinion in August 2020.

==Reviews==

Along its rather slow path, the document has been reviewed twice by the
ISE, by Tero as expert for the registry, and by Paul Hoffman as an IPsec
expert.

The reviews led to a number of updates to fully address the issues
raised.

Details of the reviews can be retrieved on request.

==Remaining Nits and Edits==

There are some nits around the use of BCP 14 language that the authors
will resolve in a new revision.

2021-12-16
04 Adrian Farrel ISE state changed to In ISE Review from Response to Review Needed
2021-12-14
04 (System) Revised ID Needed tag cleared
2021-12-14
04 Michael Jenkins New version available: draft-corcoran-cnsa-ipsec-profile-04.txt
2021-12-14
04 (System) New version approved
2021-12-14
04 (System) Request for posting confirmation emailed to previous authors: Laura Corcoran , Michael Jenkins
2021-12-14
04 Michael Jenkins Uploaded new revision
2021-12-08
03 Adrian Farrel Tag Revised I-D Needed set.
2021-12-08
03 Adrian Farrel ISE state changed to Response to Review Needed from Finding Reviewers
2021-12-06
03 Adrian Farrel ISE state changed to Finding Reviewers from In ISE Review
2021-12-06
03 Michael Jenkins New version available: draft-corcoran-cnsa-ipsec-profile-03.txt
2021-12-06
03 (System) New version approved
2021-12-06
03 (System) Request for posting confirmation emailed to previous authors: Laura Corcoran , Michael Jenkins
2021-12-06
03 Michael Jenkins Uploaded new revision
2021-11-25
02 (System) Document has expired
2021-05-24
02 (System) Revised ID Needed tag cleared
2021-05-24
02 Michael Jenkins New version available: draft-corcoran-cnsa-ipsec-profile-02.txt
2021-05-24
02 (System) New version approved
2021-05-24
02 (System) Request for posting confirmation emailed to previous authors: Laura Corcoran , Michael Jenkins
2021-05-24
02 Michael Jenkins Uploaded new revision
2021-03-19
01 Adrian Farrel Tag Revised I-D Needed set.
2021-02-18
01 (System) Document has expired
2020-08-17
01 Adrian Farrel ISE state changed to In ISE Review from Submission Received
2020-08-17
01 Michael Jenkins New version available: draft-corcoran-cnsa-ipsec-profile-01.txt
2020-08-17
01 (System) New version approved
2020-08-17
00 Adrian Farrel Intended Status changed to Informational from None
2020-08-17
00 Adrian Farrel ISE state changed to Submission Received
2020-08-17
00 Adrian Farrel Notification list changed to Adrian Farrel <rfc-ise@rfc-editor.org>
2020-08-17
00 Adrian Farrel Document shepherd changed to Adrian Farrel
2020-08-17
00 Adrian Farrel Stream changed to ISE from None
2020-08-14
01 (System) Request for posting confirmation emailed to previous authors: Laura Corcoran , Michael Jenkins
2020-08-14
01 Michael Jenkins Uploaded new revision
2020-06-06
00 (System) Document has expired
2019-12-04
00 Michael Jenkins New version available: draft-corcoran-cnsa-ipsec-profile-00.txt
2019-12-04
00 (System) New version approved
2019-12-04
00 Michael Jenkins Request for posting confirmation emailed  to submitter and authors: Laura Corcoran , Michael Jenkins
2019-12-04
00 Michael Jenkins Uploaded new revision