phase 1 Authenticated With Public Key Encryption
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
hi i seemed to have confused myself with something pretty basic. when we use automatic method of key exchange,we are putting the RSA keys of the communicating machines in ipsec.conf under the respective section. what i assumed is that this is a way of public key encryption wherein only the DNS query of RSA keys is prevented as we already have the keys exchanged, going by this anlaogy the sequence of messages during the phase 1 exchange should be as per sections 5.2-"5.2 Phase 1 Authenticated With Public Key Encryption" and 5.3- "5.3 Phase 1 Authenticated With a Revised Mode of Public Key Encryption" in IKE RFC 2409. i just wanted to confirm if freeswan is adhering to these 2 ways and which one under what conditions. thanks and regards.