<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.eronen-ipsec-ikev2-eap-auth" target="https://datatracker.ietf.org/doc/html/draft-eronen-ipsec-ikev2-eap-auth-07">
   <front>
      <title>An Extension for EAP-Only Authentication in IKEv2</title>
      <author initials="P." surname="Eronen" fullname="Pasi Eronen">
         <organization>Nokia</organization>
      </author>
      <author initials="Y." surname="Sheffer" fullname="Yaron Sheffer">
         <organization>Check Point</organization>
      </author>
      <author initials="H." surname="Tschofenig" fullname="Hannes Tschofenig">
         <organization>Nokia Siemens Networks</organization>
      </author>
      <date month="October" day="20" year="2009" />
      <abstract>
	 <t>IKEv2 specifies that EAP authentication must be used together with
public key signature based responder authentication.  This is
necessary with old EAP methods that provide only unilateral
authentication using, e.g., one-time passwords or token cards.

This document specifies how EAP methods that provide mutual
authentication and key agreement can be used to provide extensible
responder authentication for IKEv2 based on methods other than public
key signatures.
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-eronen-ipsec-ikev2-eap-auth-07" />
   
</reference>
