[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Crypto-agility work item



The fundamental goal of this work is to develop an openly specified, secure, interoperable mechanism for the negotiation of cryptographic algorithms within RADIUS. This includes algorithms for per-packet authentication and integrity protection, as well as keywrap.

The focus is on negotiation of cryptographic algorithms for existing RADIUS security mechanisms. It is not about fundamental changes to the RADIUS security model, or changes to AAA key management models (that work is occurring in EAP WG).

While this work item may enable implementations to satisfy FIPS 140-2 requirements, there are no guarantees that NIST will bless the resulting specification, or that the algorithms to be supported will remain on the list of FIPS 140-2 approved algorithms indefinitely.



--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>