It looks like HP Labs may have proven that the EC2N groups in IKE (RFC 2409 and RFC 2412) are weak. There was debate on this list long ago on the dangers of using "composite curves". The article is located at: http://www.hpl.hp.com/news/ecc.html Paul