cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
603
Views
5
Helpful
1
Replies

Ikev2 Suite b Certification RFC Requirements

broadleon
Level 1
Level 1

Hi 

 

Im looking to build a Windows Server Certification Authority that is in accordance with RFC 5759 (NSA Suite B cryptography). 

 

I will be using IKEV2 and looking at using cetificates that are:

 

CSP:  ECDSA_P384#Microsoft Software Key Storage Provider
Key Length: 384
Hash Algorithm: SHA-384

 

 RFC 5759  requirements:

 

The RFC states that the following extensions must be present: subjectKeyIdentifier (SKI), keyUsage, and basicConstraints.  Furthermore it states that the keyUsage extension must be marked as critical, and that the keyCertSign and CRLSign bits must be set.  All other bits (except for digital signature and non-repudiation, which may be setmust not be set.

 

Will these certificates work for Ikev2 in a mixed platform of IOS Routers (2951 sec +) and ASA's (5506 Sec +) ?

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes, as long as you are running relatively recent software versions on them.

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes, as long as you are running relatively recent software versions on them.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: