BGPsec Protocol Specification
RFC 8205, “BGPsec Protocol Specification”, is a Proposed Standard document published in September 2017 by M. Lepinski, K. Sriram. It has since been updated by RFC 8206. The canonical text is published by the RFC Editor.
Abstract
This document describes BGPsec, an extension to the Border Gateway Protocol (BGP) that provides security for the path of Autonomous Systems (ASes) through which a BGP UPDATE message passes. BGPsec is implemented via an optional non-transitive BGP path attribute that carries digital signatures produced by each AS that propagates the UPDATE message. The digital signatures provide confidence that every AS on the path of ASes listed in the UPDATE message has explicitly authorized the advertisement of the route.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8205 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8204 Benchmarking Virtual Switches in the Open Platform for NFV
- RFC 8206 BGPsec Considerations for Autonomous System Migration
- RFC 8203 BGP Administrative Shutdown Communication
- RFC 8207 BGPsec Operational Considerations
- RFC 8202 IS-IS Multi-Instance
- RFC 8208 BGPsec Algorithms, Key Formats, and Signature Formats
- RFC 8201 Path MTU Discovery for IP version 6
- RFC 8209 A Profile for BGPsec Router Certificates, Certificate Revocation Lists, and Certification Requests