I haven't looked if we have support, but gre(4) w/ ipv6 address and stf(4) seem to be best options out there for secure v6 tunnels.That sounds... bizarre.
According to ipv6book.ca, M. Blanchet. It's a good read, except OpenBSD/NetBSD are neglected (probably becase of the stf(4)/6to4(4) absence).
He also doesn't talk about _securing_ GRE tunnels, altough the logical assumption would be transport mode ipsec between v4 endpoints
~BAS

