The TCP Authentication Option
RFC 5925, “The TCP Authentication Option”, is a Proposed Standard document published in June 2010 by J. Touch, A. Mankin, R. Bonica. It obsoletes RFC 2385. The canonical text is published by the RFC Editor.
Abstract
This document specifies the TCP Authentication Option (TCP-AO), which obsoletes the TCP MD5 Signature option of RFC 2385 (TCP MD5). TCP-AO specifies the use of stronger Message Authentication Codes (MACs), protects against replays even for long-lived TCP connections, and provides more details on the association of security with TCP connections than TCP MD5. TCP-AO is compatible with either a static Master Key Tuple (MKT) configuration or an external, out-of-band MKT management mechanism; in either case, TCP-AO also protects connections when using the same MKT across repeated instances of a connection, using traffic keys derived from the MKT, and coordinates MKT changes between endpoints. The result is intended to support current infrastructure uses of TCP MD5, such as to protect long-lived connections (as used, e.g., in BGP and LDP), and to support a larger set of MACs with minimal other system and operational changes. TCP-AO uses a different option identifier than TCP MD5, even though TCP-AO and TCP MD5 are never permitted to be used simultaneously. TCP-AO supports IPv6, and is fully compatible with the proposed requirements for the replacement of TCP MD5. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5925 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5924 Extended Key Usage for Session Initiation Protocol X.509 Certificates
- RFC 5926 Cryptographic Algorithms for the TCP Authentication Option
- RFC 5923 Connection Reuse in the Session Initiation Protocol
- RFC 5927 ICMP Attacks against TCP
- RFC 5922 Domain Certificates in the Session Initiation Protocol
- RFC 5928 Traversal Using Relays around NAT Resolution Mechanism
- RFC 5921 A Framework for MPLS in Transport Networks
- RFC 5929 Channel Bindings for TLS