RFC 7474 · PROPOSED STANDARD · 2015

Security Extension for OSPFv2 When Using Manual Key Management

Overview

RFC 7474, “Security Extension for OSPFv2 When Using Manual Key Management”, is a Proposed Standard document published in April 2015 by M. Bhatia, S. Hartman, D. Zhang, A. Lindem. It updates RFC 2328, RFC 5709. The canonical text is published by the RFC Editor.

Abstract

The current OSPFv2 cryptographic authentication mechanism as defined in RFCs 2328 and 5709 is vulnerable to both inter-session and intra- session replay attacks when using manual keying. Additionally, the existing cryptographic authentication mechanism does not cover the IP header. This omission can be exploited to carry out various types of attacks.

This document defines changes to the authentication sequence number mechanism that will protect OSPFv2 from both inter-session and intra- session replay attacks when using manual keys for securing OSPFv2 protocol packets. Additionally, we also describe some changes in the cryptographic hash computation that will eliminate attacks resulting from OSPFv2 not protecting the IP header.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 7474 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC updates
RFC 2328 RFC 5709
Other RFCs from 2015

Who Is Online

In total there are 64 users online: 0 registered, 57 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: Applebot Baiduspider Bingbot Googlebot Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372