24.05.2014 Views

AIX Version 4.3 Differences Guide

AIX Version 4.3 Differences Guide

AIX Version 4.3 Differences Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

7.1.11 IPv6 and IPSec-Related RFCs Implementation<br />

Table 36 shows the RFCs that have been implemented in the IP <strong>Version</strong> 6<br />

support included with <strong>AIX</strong> <strong>Version</strong> <strong>4.3</strong>.0. Please consult these RFCs, or their<br />

successors, for the latest information on IP <strong>Version</strong> 6 protocols.<br />

Table 36. RFCs Implemented in <strong>AIX</strong> <strong>Version</strong> <strong>4.3</strong>.0<br />

RFC number<br />

RFC Title<br />

1825 Security Architecture for the Internet Protocol<br />

1826 IP Authentification Header (AH)<br />

1827 IP Encapsulating Security Payload (ESP)<br />

1828 IP Authentification Using Keyed MD5<br />

1829 The ESP DES-CBC Transform<br />

1883 Internet Protocol, <strong>Version</strong> 6 (IPv6) Specification<br />

1884 IP <strong>Version</strong> 6 Addressing Architecture<br />

1885 Internet Control Message Protocol (ICMPv6) for IPv6<br />

1933 Transition Mechanisms for IPv6 Hosts and Routers<br />

1970 IPv6 Stateless Address Autoconfiguration<br />

1971 Neighbor Discovery for IP <strong>Version</strong> 6 (IPv6)<br />

7.2 IP Security Enhancements (<strong>4.3</strong>.1)<br />

<strong>AIX</strong> <strong>4.3</strong>.1 has added new functions to IP Security:<br />

• Triple-DES is an additional choice for U.S. and Canada customers.<br />

• Performance improvements have been made to the CDMF and DES<br />

encryption.<br />

• The filter table now supports unlimited number of rules.<br />

• Any combination of installed authentication and encryption algorithms can be<br />

used for ESP with Authentication.<br />

In addition, new parameters have been added to the following IPSec commands:<br />

• exptun<br />

• imptun<br />

• mktun<br />

• rmfilt<br />

7.3 TCP/IP Command Security Enhancement (<strong>4.3</strong>.1)<br />

<strong>AIX</strong> <strong>Version</strong> <strong>4.3</strong>.1 offers secure remote TCP/IP commands: rsh, rcp, rlogin, telnet,<br />

and ftp. With this capability, Kerberos 5 authentication is used between these<br />

commands and server daemons, avoiding the need for user passwords to pass in<br />

the clear on the network. Instead, Kerberos 5 credentials are used to authenticate<br />

users. User credentials can be forwarded to the server.<br />

166 <strong>AIX</strong> <strong>Version</strong> <strong>4.3</strong> <strong>Differences</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!