Skip to main content

IKE Challenge/Response for Authenticated Cryptographic Keys (Revised)

Document Type Expired Internet-Draft (individual)
Expired & archived
Authors Dan Harkins , Derrell Piper
Last updated 2000-08-25
RFC stream (None)
Intended RFC status (None)
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:


This memo describes a new IKE authentication method ([HC98]) which provides for mutual authentication when one side is using a legacy- based secret-key authentication technique such as RADIUS, SecurID, or OTP and the other side is using public-key authentication, with optional digital certificates. The generic protocol described herein is an open-ended IKE phase 1 exchange ([HC98]). The result of this exchange is a mutually authenticated IKE security association ([HC98]). The keys that are derived from this SA are also authenticated and thereby convey this state to any SA's created from it for any other security service, such as IPsec [Pip98].


Dan Harkins
Derrell Piper

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)