IETF RFC 5386
Better-Than-Nothing Security: An Unauthenticated Mode of IPsec
| Organization: | IETF |
| Publication Date: | 1 November 2008 |
| Status: | active |
| Page Count: | 11 |
scope:
This document specifies how to use the Internet Key Exchange
(IKE) protocols, such as IKEv1 and IKEv2, to setup
"unauthenticated" security associations (SAs) for use with the
IPsec Encapsulating Security Payload (ESP) and the IPsec
Authentication Header (AH). No changes to IKEv2 bits-on-the-wire
are required, but Peer Authorization Database (PAD) and Security
Policy Database (SPD) extensions are specified. Unauthenticated
IPsec is herein referred to by its popular acronym, "BTNS"
(Better-Than-Nothing
Document History