RFC 9838
Group Key Management Using the Internet Key Exchange Protocol Version 2 (IKEv2), November 2025
- File formats:

- Also available: XML file for editing
- Status:
- PROPOSED STANDARD
- Obsoletes:
- RFC 6407
- Authors:
- V. Smyslov
B. Weis - Stream:
- IETF
- Source:
- ipsecme (sec)
Cite this RFC: TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC9838
Discuss this RFC: Send questions or comments to the mailing list ipsec@ietf.org
Other actions: Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 9838
Abstract
This document presents an extension to the Internet Key Exchange Protocol Version 2 (IKEv2) for the purpose of group key management. The protocol is in conformance with the Multicast Security (MSEC) Group Key Management architecture, which contains two components: member registration and group rekeying. Both components are required for a Group Controller/Key Server (GCKS) to provide authorized Group Members (GMs) with IPsec Group Security Associations (GSAs). The GMs then exchange IP multicast or other group traffic as IPsec packets.
This document obsoletes RFC 6407.
For the definition of Status, see RFC 2026.
For the definition of Stream, see RFC 8729.