HP-UX IPSec Version A.03.02.02 Administrator's Guide HP-UX 11i version 2 and HP-UX 11i version 3 (762800-001, April 2014)

“IKE support for multiple hash, encryption, and group values” (page 22)
“IKE Support for Diffie-Hellman groups 5 and 14” (page 22)
“IKE support for AES128-CBC encryption” (page 22)
Authentication record changes” (page 22)
Authentication records are mandatory” (page 22)
Authentication records specify the IKE (key management protocol) version” (page 23)
Authentication records include a priority value” (page 22)
Authentication records support the AUTOCONF flag” (page 23)
Authentication records support subtrees and address ranges for remote ID matching”
(page 23)
“Hexadecimal storage for preshared key values starting with 0x” (page 23)
“Host and tunnel policy changes” (page 23)
“Nested transforms and DES Ttransforms are obsolete” (page 23)
“Support for fallback to clear in host policies” (page 23)
“Support for multiple source and destination arguments in host and tunnel policies
(page 24)
“Support for IP address ranges in tunnel policies” (page 24)
“Support for IP address and port number ranges in host policies” (page 24)
“Port numbers and services are ignored in tunnel policies” (page 24)
“Support for ICMPv4 and ICMPv6 type codes in host policies” (page 24)
“Support for IPv6 mobility header type codes in host policies” (page 24)
“Certificate changes” (page 24)
“The ipsec_config add cert command is deprecated” (page 24)
“Support for 4096 bit key pairs for certificates” (page 25)
“Support for PKCS#12 certificates” (page 25)
“Certificate retrieval from LDAP directories” (page 25)
“Support for multiple level public key infrastructures” (page 25)
“Certificate Revocation List cron file change” (page 25)
“Support for RFC 4301 security processing for ICMP errors” (page 25)
“Profile file changes” (page 25)
“Mobile IPv6 support is obsolete” (page 26)
“Gateway policies are obsolete” (page 26)
IKE policy changes
The following sections describe product changes related to IKE policies.
20