Skip to main content

Multi-Domain Authentication and Key Exchange Protocol

Document Type Expired Internet-Draft (individual)
Expired & archived
Author Kai Martius
Last updated 1999-07-21
RFC stream (None)
Intended RFC status (None)
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:


This document describes a protocol which allows to authenticate systems and establish Security Associations in networks with different domains of security. The protocol is not only end-to-end, but it involves all participating systems in a single exchange. Further it allows security gateways to derive sub-policies for crossing (encrypted) IPSec-traffic from 'conventional' packet filtering rules in a trusted manner.


Kai Martius

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)