IKEv2: active user identity protection

I would also strongly support active user identity confidentiality protection for the initiator within IKEv2. The issue was recently raised by several people. We analysed the topic in the SHAMAN project and considered it a significant security requirement. It seems particularly important for wireless connections where attacks can easily be launched.

