Secure Proxy ND Support for SEcure Neighbor Discovery
RFC 6496, “Secure Proxy ND Support for SEcure Neighbor Discovery”, is an Experimental document published in February 2012 by S. Krishnan, J. Laganier, M. Bonola, A. Garcia-Martinez. The canonical text is published by the RFC Editor.
Abstract
SEcure Neighbor Discovery (SEND) specifies a method for securing Neighbor Discovery (ND) signaling against specific threats. As defined today, SEND assumes that the node sending an ND message is the owner of the address from which the message is sent and/or possesses a key that authorizes the node to act as a router, so that it is in possession of the private key or keys used to generate the digital signature on each message. This means that the Proxy ND signaling performed by nodes that do not possess knowledge of the address owner's private key and/or knowledge of a router's key cannot be secured using SEND. This document extends the current SEND specification in order to secure Proxy ND operation. This document defines an Experimental Protocol for the Internet community.
What “Experimental” means
Describes a specification that is part of a research or development effort, published so the community can gain experience with it.
The canonical text of RFC 6496 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6495 Subject Key Identifier SEcure Neighbor Discovery Name Type Fields
- RFC 6497 BCP 47 Extension T - Transformed Content
- RFC 6494 Certificate Profile and Certificate Management for SEcure Neighbor Discovery
- RFC 6498 Media Gateway Control Protocol Voiceband Data Package and General-Purpose Media Descriptor Parameter Package
- RFC 6493 The Resource Public Key Infrastructure Ghostbusters Record
- RFC 6492 A Protocol for Provisioning Resource Certificates
- RFC 6491 Resource Public Key Infrastructure Objects Issued by IANA
- RFC 6501 Conference Information Data Model for Centralized Conferencing