Authentication and Confidentiality in Protocol Independent Multicast Sparse Mode Link-Local Messages
RFC 5796, “Authentication and Confidentiality in Protocol Independent Multicast Sparse Mode Link-Local Messages”, is a Proposed Standard document published in March 2010 by W. Atwood, S. Islam, M. Siami. It updates RFC 4601. The canonical text is published by the RFC Editor.
Abstract
RFC 4601 mandates the use of IPsec to ensure authentication of the link-local messages in the Protocol Independent Multicast - Sparse Mode (PIM-SM) routing protocol. This document specifies mechanisms to authenticate the PIM-SM link-local messages using the IP security (IPsec) Encapsulating Security Payload (ESP) or (optionally) the Authentication Header (AH). It specifies optional mechanisms to provide confidentiality using the ESP. Manual keying is specified as the mandatory and default group key management solution. To deal with issues of scalability and security that exist with manual keying, optional support for an automated group key management mechanism is provided. However, the procedures for implementing automated group key management are left to other documents. This document updates RFC 4601. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5796 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5795 The RObust Header Compression Framework
- RFC 5797 FTP Command and Extension Registry
- RFC 5794 A Description of the ARIA Encryption Algorithm
- RFC 5798 Virtual Router Redundancy Protocol Version 3 for IPv4 and IPv6
- RFC 5793 PB-TNC: A Posture Broker Protocol Compatible with Trusted Network Connect
- RFC 5792 PA-TNC: A Posture Attribute Protocol Compatible with Trusted Network Connect
- RFC 5791 RFC 2731 Is Obsolete
- RFC 5801 Using Generic Security Service Application Program Interface Mechanisms in Simple Authentication and Security Layer : The GS2 Mechanism Family