Re: IPSec in 2.5 Kernel?

Henry Spencer <[email protected]> Thu, 20 Mar 2003 19:11:02 -0500 (EST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
On Thu, 20 Mar 2003, Jim Carter wrote:
> It would seem useful to me to allow anonymous ipsec, e.g. Diffie-Hellman
> key exchange and that's all.  You don't know who you're talking to, but
> "they" can't snoop your packets...

There is, unfortunately, no provision for it in IPsec.  Aside from the
obvious possibility of just picking a "standard secret" for shared-secret
authentication, that is.  (I have a vague memory of an April 1st RFC which
actually defined one, but I don't seem to have it on file.)  All IKE variants
require some form of endpoint authentication.

                                                          Henry Spencer
                                                       [email protected]