Product Specifications

HP-UX IPSec Transforms

ESP-NULL-HMAC-MD5

ESP header and trailer, but nothing is encrypted. An ICV is generated using

HMAC-MD5.

ESP-NULL-HMAC-SHA1

ESP header and trailer, but nothing is encrypted. An ICV is generated using

HMAC-SHA1.

Transform Lifetime Negotiation

The transform lifetimes configured are the preferred lifetimes. The actual lifetimes used depends on negotiations with the remote system.

If the local system initiates the IPSec negotiations, the ISAKMP daemon will send the preferred lifetime to the remote system. The remote system may process this value in any manner according to the IPSec protocol specification.

If the remote system initiates the IPSec negotiations, the ISAKMP daemon will accept the lifetime sent by the remote system, within the range specified by the IPSec protocol.

286

Appendix A