Message Authentication Code for the Network Time Protocol
RFC 8573, “Message Authentication Code for the Network Time Protocol”, is a Proposed Standard document published in June 2019 by A. Malhotra, S. Goldberg. It updates RFC 5905. It has since been updated by RFC 9748. The canonical text is published by the RFC Editor.
Abstract
The Network Time Protocol (NTP), as described in RFC 5905, states that NTP packets should be authenticated by appending NTP data to a 128-bit key and hashing the result with MD5 to obtain a 128-bit tag. This document deprecates MD5-based authentication, which is considered too weak, and recommends the use of AES-CMAC as described in RFC 4493 as a replacement.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8573 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8572 Secure Zero Touch Provisioning
- RFC 8574 cite-as: A Link Relation to Convey a Preferred URI for Referencing
- RFC 8571 BGP - Link State Advertisement of IGP Traffic Engineering Performance Metric Extensions
- RFC 8575 YANG Data Model for the Precision Time Protocol
- RFC 8570 IS-IS Traffic Engineering Metric Extensions
- RFC 8576 Internet of Things Security: State of the Art and Challenges
- RFC 8569 Content-Centric Networking Semantics
- RFC 8577 Signaling RSVP-TE Tunnels on a Shared MPLS Forwarding Plane