Issues with Existing Cryptographic Protection Methods for Routing Protocols
RFC 6039, “Issues with Existing Cryptographic Protection Methods for Routing Protocols”, is an Informational document published in October 2010 by V. Manral, M. Bhatia, J. Jaeggli, R. White. The canonical text is published by the RFC Editor.
Abstract
Routing protocols have been extended over time to use cryptographic mechanisms to ensure that data received from a neighboring router has not been modified in transit and actually originated from an authorized neighboring router.
The cryptographic mechanisms defined to date and described in this document rely on a digest produced with a hash algorithm applied to the payload encapsulated in the routing protocol packet.
This document outlines some of the limitations of the current mechanism, problems with manual keying of these cryptographic algorithms, and possible vectors for the exploitation of these limitations. This document is not an Internet Standards Track specification; it is published for informational purposes.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 6039 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6038 Two-Way Active Measurement Protocol Reflect Octets and Symmetrical Size Features
- RFC 6040 Tunnelling of Explicit Congestion Notification
- RFC 6037 Cisco Systems' Solution for Multicast in BGP/MPLS IP VPNs
- RFC 6041 Forwarding and Control Element Separation Applicability Statement
- RFC 6036 Emerging Service Provider Scenarios for IPv6 Deployment
- RFC 6042 Transport Layer Security Authorization Using KeyNote
- RFC 6035 Session Initiation Protocol Event Package for Voice Quality Reporting
- RFC 6034 Unicast-Prefix-Based IPv4 Multicast Addresses