Security Policy System

Document Type Expired Internet-Draft (ipsec WG)
Authors Luis Sanchez  , Matt Condell 
Last updated 1999-01-05
Stream Internet Engineering Task Force (IETF)
Expired & archived
pdf htmlized bibtex
Stream WG state WG Document
Document shepherd No shepherd assigned
IESG IESG state Expired
Consensus Boilerplate Unknown
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This document describes a distributed system that provides the mechanisms needed for discovering, accessing and processing security policy information of hosts, subnets or networks of a security domain. In this system policy clients and servers exchange information using the Security Policy Protocol. The protocol defines how the policy information is exchanged, processed, and protected by clients and servers. The system accommodates topology changes, hence policy changes, rather easily without the scalability constraints imposed by static reconfiguration of each client. The protocol is extensible and flexible. It allows the exchange of complex policy objects between clients and servers.


Luis Sanchez (
Matt Condell (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)