Markdown Version | Session Recording

Session Date/Time: 06 Nov 2025 19:30

IPSECME

Summary

The IPSECME session included an update on RFC publications, document status in the working group queue, and presentations on several key drafts. Significant discussions focused on the PFSInfo draft, which aims to improve negotiation of Child SA key exchange methods, and the Enhanced ESP draft, which addressed transport mode support and header changes. The Downgrade Prevention draft garnered broad support as a necessary mitigation for IKEv2 vulnerabilities, especially in the context of Post-Quantum Cryptography (PQC). New KEM-based authentication and KEM algorithm drafts (Frodo KEM, McLeese KEM) were presented, highlighting challenges and opportunities for integrating PQC into IKEv2. The session concluded with updates on the Beat Mode draft, and open discussions on experimental RFCs and IPsec's interaction with network reordering.

Key Discussion Points

Agenda and Document Status

PFSInfo Draft (draft-kivinen-ipsecme-pfsinfo)

Enhanced ESP Draft (draft-ietf-ipsecme-eesp)

EESP X Version 2 Draft (draft-ietf-ipsecme-eespxv2)

Downgrade Prevention Draft (draft-ietf-ipsecme-downgrade-prevention)

CAM-based Authentication for IKEv2 Draft (draft-ietf-ipsecme-cam-auth)

Frodo KEM in IKEv2 with Hybrid and PQC KEMs Draft (draft-ietf-ipsecme-frodo-kem-ikev2)

McLeese KEM in IKEv2 Draft (draft-smyslov-ipsecme-mcbits-ikev2)

Beat Mode Update Draft (draft-moskowitz-ipsecme-beat-mode-update)

Open Discussion

Decisions and Action Items

Next Steps