<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><div><br><br>Sent from my iPhone</div><div><br>Begin forwarded message:<br><br></div><blockquote type="cite"><div><b>From:</b> John Mattsson <<a href="mailto:john.mattsson@ericsson.com">john.mattsson@ericsson.com</a>><br><b>Date:</b> November 23, 2016 at 08:23:48 EST<br><b>To:</b> "<a href="mailto:ipsec@ietf.org">ipsec@ietf.org</a>" <<a href="mailto:ipsec@ietf.org">ipsec@ietf.org</a>><br><b>Subject:</b> <b>[IPsec] Updated 3GPP Profile for IKEv2</b><br><br></div></blockquote><blockquote type="cite"><div><span>Hi,</span><br><span></span><br><span>FYI, 3GPP recently updated its IKEv2 profile. The current profiles for</span><br><span>IKEv2 and ESP looks like this (only the relevant part of 3GPP TS 33.210</span><br><span>and TS 33.310):</span><br><span></span><br><span><a href="https://www.scribd.com/document/332057984/3GPP-IPsec-Profile-Nov-2016">https://www.scribd.com/document/332057984/3GPP-IPsec-Profile-Nov-2016</a></span><br><span></span><br><span></span><br><span>Main changes are:</span><br><span></span><br><span>- SHA-1 signatures of all kinds are forbidden.</span><br><span>- Digital Signatures and Hash Algorithm Notification [RFC7427] are</span><br><span>mandatory to support.</span><br><span></span><br><span>Comments of any kind from the IPSECME WG are very welcome.</span><br><span></span><br><span>I will drive another update of the 3GPP profiles as soon as 4307bis and</span><br><span>7321bis are published.</span><br><span></span><br><span>Cheers,</span><br><span>John</span><br><span></span><br><span>_______________________________________________</span><br><span>IPsec mailing list</span><br><span><a href="mailto:IPsec@ietf.org">IPsec@ietf.org</a></span><br><span><a href="https://www.ietf.org/mailman/listinfo/ipsec">https://www.ietf.org/mailman/listinfo/ipsec</a></span><br></div></blockquote></body></html>