[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Crypto-agility work item
The fundamental goal of this work is to develop an openly specified, secure,
interoperable mechanism for the negotiation of cryptographic algorithms
within RADIUS. This includes algorithms for per-packet authentication and
integrity protection, as well as keywrap.
The focus is on negotiation of cryptographic algorithms for existing RADIUS
security mechanisms. It is not about fundamental changes to the RADIUS
security model, or changes to AAA key management models (that work is
occurring in EAP WG).
While this work item may enable implementations to satisfy FIPS 140-2
requirements, there are no guarantees that NIST will bless the resulting
specification, or that the algorithms to be supported will remain on the
list of FIPS 140-2 approved algorithms indefinitely.
--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>