A Profile for BGPsec Router Certificates, Certificate Revocation Lists, and Certification Requests
RFC 8209, “A Profile for BGPsec Router Certificates, Certificate Revocation Lists, and Certification Requests”, is a Proposed Standard document published in September 2017 by M. Reynolds, S. Turner, S. Kent. It updates RFC 6487. The canonical text is published by the RFC Editor.
Abstract
This document defines a standard profile for X.509 certificates used to enable validation of Autonomous System (AS) paths in the Border Gateway Protocol (BGP), as part of an extension to that protocol known as BGPsec. BGP is the standard for inter-domain routing in the Internet; it is the "glue" that holds the Internet together. BGPsec is being developed as one component of a solution that addresses the requirement to provide security for BGP. The goal of BGPsec is to provide full AS path validation based on the use of strong cryptographic primitives. The end entity (EE) certificates specified by this profile are issued to routers within an AS. Each of these certificates is issued under a Resource Public Key Infrastructure (RPKI) Certification Authority (CA) certificate. These CA certificates and EE certificates both contain the AS Resource extension. An EE certificate of this type asserts that the router or routers holding the corresponding private key are authorized to emit secure route advertisements on behalf of the AS(es) specified in the certificate. This document also profiles the format of certification requests and specifies Relying Party (RP) certificate path validation procedures for these EE certificates. This document extends the RPKI; therefore, this document updates the RPKI Resource Certificates Profile (RFC 6487).
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8209 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8208 BGPsec Algorithms, Key Formats, and Signature Formats
- RFC 8210 The Resource Public Key Infrastructure to Router Protocol, Version 1
- RFC 8207 BGPsec Operational Considerations
- RFC 8211 Adverse Actions by a Certification Authority or Repository Manager in the Resource Public Key Infrastructure
- RFC 8206 BGPsec Considerations for Autonomous System Migration
- RFC 8212 Default External BGP Route Propagation Behavior without Policies
- RFC 8205 BGPsec Protocol Specification
- RFC 8213 Security of Messages Exchanged between Servers and Relay Agents