| |
| | RFC 2409 (rfc2409) - The Internet Key Exchange (IKE) (Site not responding. Last check: 2007-10-22) |
 | | Exchanges conform to standard ISAKMP payload syntax, attribute encoding, timeouts and retransmits of messages, and informational messages-- e.g a notify response is sent when, for example, a proposal is unacceptable, or a signature verification or decryption was unsuccessful, etc. The SA payload MUST precede all other payloads in a phase 1 exchange. |
 | | In this mode, the nonce is still encrypted using the public key of the peer, however the peer's identity (and the certificate if it is sent) is encrypted using the negotiated symmetric encryption algorithm (from the SA payload) with a key derived from the nonce. |
 | | Ke_i and Ke_r are keys to the symmetric encryption algorithm negotiated in the SA payload exchange. |
| www.faqs.org /rfcs/rfc2409.html (9915 words) |
|