Summary of Cryptographic Authentication Algorithm Implementation Requirements for Routing Protocols
RFC 6094, “Summary of Cryptographic Authentication Algorithm Implementation Requirements for Routing Protocols”, is an Informational document published in February 2011 by M. Bhatia, V. Manral. The canonical text is published by the RFC Editor.
Abstract
The routing protocols Open Shortest Path First version 2 (OSPFv2), Intermediate System to Intermediate System (IS-IS), and Routing Information Protocol (RIP) currently define cleartext and MD5 (Message Digest 5) methods for authenticating protocol packets. Recently, effort has been made to add support for the SHA (Secure Hash Algorithm) family of hash functions for the purpose of authenticating routing protocol packets for RIP, IS-IS, and OSPF.
To encourage interoperability between disparate implementations, it is imperative that we specify the expected minimal set of algorithms, thereby ensuring that there is at least one algorithm that all implementations will have in common.
Similarly, RIP for IPv6 (RIPng) and OSPFv3 support IPsec algorithms for authenticating their protocol packets.
This document examines the current set of available algorithms, with interoperability and effective cryptographic authentication protection being the principal considerations. Cryptographic authentication of these routing protocols requires the availability of the same algorithms in disparate implementations. It is desirable that newly specified algorithms should be implemented and available in routing protocol implementations because they may be promoted to requirements at some future time. This document is not an Internet Standards Track specification; it is published for informational purposes.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 6094 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6093 On the Implementation of the TCP Urgent Mechanism
- RFC 6095 Extending YANG with Language Abstractions
- RFC 6092 Recommended Simple Security Capabilities in Customer Premises Equipment for Providing Residential IPv6 Internet Service
- RFC 6096 Stream Control Transmission Protocol Chunk Flags Registration
- RFC 6091 Using OpenPGP Keys for Transport Layer Security Authentication
- RFC 6097 Local Mobility Anchor Discovery for Proxy Mobile IPv6
- RFC 6090 Fundamental Elliptic Curve Cryptography Algorithms
- RFC 6089 Flow Bindings in Mobile IPv6 and Network Mobility Basic Support