IS-IS Cryptographic Authentication
RFC 5304, “IS-IS Cryptographic Authentication”, is a Proposed Standard document published in October 2008 by T. Li, R. Atkinson. It updates RFC 1195. It obsoletes RFC 3567. It has since been updated by RFC 6232, RFC 6233. The canonical text is published by the RFC Editor.
Abstract
This document describes the authentication of Intermediate System to Intermediate System (IS-IS) Protocol Data Units (PDUs) using the Hashed Message Authentication Codes - Message Digest 5 (HMAC-MD5) algorithm as found in RFC 2104. IS-IS is specified in International Standards Organization (ISO) 10589, with extensions to support Internet Protocol version 4 (IPv4) described in RFC 1195. The base specification includes an authentication mechanism that allows for multiple authentication algorithms. The base specification only specifies the algorithm for cleartext passwords. This document replaces RFC 3567.
This document proposes an extension to that specification that allows the use of the HMAC-MD5 authentication algorithm to be used in conjunction with the existing authentication mechanisms. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5304 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5303 Three-Way Handshake for IS-IS Point-to-Point Adjacencies
- RFC 5305 IS-IS Extensions for Traffic Engineering
- RFC 5302 Domain-Wide Prefix Distribution with Two-Level IS-IS
- RFC 5306 Restart Signaling for IS-IS
- RFC 5301 Dynamic Hostname Exchange Mechanism for IS-IS
- RFC 5307 IS-IS Extensions in Support of Generalized Multi-Protocol Label Switching
- RFC 5308 Routing IPv6 with IS-IS
- RFC 5309 Point-to-Point Operation over LAN in Link State Routing Protocols