Skip to main content

IETF Last Call Review of draft-ietf-ipsecme-ikev2-pqc-auth-09
review-ietf-ipsecme-ikev2-pqc-auth-09-genart-lc-mishra-2026-07-19-00

Request Review of draft-ietf-ipsecme-ikev2-pqc-auth
Requested revision No specific revision (document currently at 09)
Type IETF Last Call Review
Team General Area Review Team (Gen-ART) (genart)
Deadline 2026-07-31
Requested 2026-07-10
Authors Tirumaleswar Reddy.K , Valery Smyslov , Scott Fluhrer
I-D last updated 2026-07-10 (Latest revision 2026-07-10)
Completed reviews Genart IETF Last Call review of -09 by Gyan Mishra
Secdir IETF Last Call review of -09 by Russ Housley
Assignment Reviewer Gyan Mishra
State Completed
Request IETF Last Call review on draft-ietf-ipsecme-ikev2-pqc-auth by General Area Review Team (Gen-ART) Assigned
Posted at https://mailarchive.ietf.org/arch/msg/gen-art/IkSyrt0RcYgKjADhNTtf38VGs_o
Reviewed revision 09
Result Almost ready
Completed 2026-07-19
review-ietf-ipsecme-ikev2-pqc-auth-09-genart-lc-mishra-2026-07-19-00
I am the assigned Gen-ART reviewer for this draft. The General Area
Review Team (Gen-ART) reviews all IETF documents being processed
by the IESG for the IETF Chair.  Please treat these comments just
like any other last call comments.

For more information, please see the FAQ at

<https://wiki.ietf.org/en/group/gen/GenArtFAQ>.

Document: draft-ietf-ipsecme-ikev2-pqc-auth-??
Reviewer: Gyan Mishra
Review Date: 2026-07-19
IETF LC End Date: 2026-07-31
IESG Telechat date: Not scheduled for a telechat

Summary:

Signature-based authentication methods are utilized in the Internet Key
Exchange Version 2 (IKEv2). The current version of the IKEv2 protocol,
specified in RFC 7296, supports traditional digital signatures.

This document specifies a generic mechanism for integrating post-quantum
cryptographic (PQC) digital signature algorithms into the IKEv2 protocol. The
approach allows for seamless inclusion of any PQC signature scheme within the
existing authentication framework of IKEv2. Additionally, it outlines how
Module-Lattice-Based Digital Signatures (ML-DSA) and Stateless Hash-Based
Digital Signatures (SLH-DSA), can be employed as authentication methods within
the IKEv2 protocol, as they have been standardized by US NIST.

I believe this specification is almost ready for publication.

One question I would like to ask the authors is related to any IANA code points
for the use of PQC for signature for IKEv2.

As this is standards track and a significant change to IKEv2 which does impact
all IPSEC implementations vendors supporting the PQM update feature.

To ensure standardization and forward and backward compatibility in the
implementation should there be a standard codepoint allocated for the drafts
update to IKEv2 for PQM signature signing.

What is the impact on SA security association rekeying during key update
intervals.  I do not see anything mentioned related but as we are using a new
PQM signing mechanism, I wonder if there is any impact and if so it should be
added to the considerations section.

Major issues:
None

Minor issues:
None

Nits/editorial comments:
None