Re: IPSec in 2.5 Kernel?
Henry Spencer <[email protected]> Thu, 20 Mar 2003 19:11:02 -0500 (EST)
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 20 Mar 2003, Jim Carter wrote:
> It would seem useful to me to allow anonymous ipsec, e.g. Diffie-Hellman
> key exchange and that's all. You don't know who you're talking to, but
> "they" can't snoop your packets...
There is, unfortunately, no provision for it in IPsec. Aside from the
obvious possibility of just picking a "standard secret" for shared-secret
authentication, that is. (I have a vague memory of an April 1st RFC which
actually defined one, but I don't seem to have it on file.) All IKE variants
require some form of endpoint authentication.
Henry Spencer
[email protected]