The Use of Galois/Counter Mode (GCM) in IPsec Encapsulating Security Payload (ESP)
RFC 4106

Approval announcement
Draft of message to be sent after approval:

From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
Cc: Internet Architecture Board <iab@iab.org>,
    RFC Editor <rfc-editor@rfc-editor.org>, 
    ipsec mailing list <ipsec@ietf.org>, 
    ipsec chair <ipsec-chairs@tools.ietf.org>
Subject: Protocol Action: 'The Use of Galois/Counter Mode (GCM) 
         in IPsec ESP' to Proposed Standard 

The IESG has approved the following document:

- 'The Use of Galois/Counter Mode (GCM) in IPsec ESP '
   <draft-ietf-ipsec-ciph-aes-gcm-01.txt> as a Proposed Standard

This document is the product of the IP Security Protocol Working Group. 

The IESG contact persons are Russ Housley and Tim Polk.

A URL of this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-ipsec-ciph-aes-gcm-01.txt

Technical Summary

  This document describes the use of the Advanced Encryption Standard
  (AES) in Galois/Counter Mode (GCM) as an IPsec Encapsulating Security
  Payload (ESP) mechanism to provide confidentiality and data origin
  authentication.

Working Group Summary

  The IPsec Working Group reviewed this document, but it is progressing
  as an Individual submission.  All of the comments provided by IPsec
  Working Group participants were supportive.

Protocol Quality

  This document was reviewed by Russ Housley for the IESG.

RFC Editor Note

  In the first paragraph of section 1, please change "IPSec" to "IPsec"
  to use the normal spelling.

  OLD:

   This document describes the use of AES in GCM mode (AES-GCM) as an
   IPSec ESP mechanism ...

  NEW:

   This document describes the use of AES in GCM mode (AES-GCM) as an
   IPsec ESP mechanism ...

  Replace section 8.3.

  OLD:

   For IKE Phase 2 negotiations, IANA has assigned <TBD> as the ESP
   Transform Identifier for AES-GCM with an eight-byte explicit IV.

  NEW:

   For IKE Phase 2 negotiations, IANA has assigned four ESP Transform
   Identifiers for AES-GCM with an eight-byte explicit IV:

      <TBD1> for AES-GCM with a 4 octet ICV;
      <TBD2> for AES-GCM with an 8 octet ICV;
      <TBD3> for AES-GCM with a 12 octet ICV; and
      <TBD4> for AES-GCM with a 16 octet ICV.

  Replace section 12.

  OLD:

   Currently, no ESP transform numbers have been assigned for use with
   the AES-GCM transform.

  NEW:

   IANA has assigned four ESP Transform Identifiers for AES-GCM with
   an eight-byte explicit IV:

      <TBD1> for AES-GCM with a 4 octet ICV;
      <TBD2> for AES-GCM with an 8 octet ICV;
      <TBD3> for AES-GCM with a 12 octet ICV; and
      <TBD4> for AES-GCM with a 16 octet ICV.