Router Keying for BGPsec
RFC 8635, “Router Keying for BGPsec”, is a Proposed Standard document published in August 2019 by R. Bush, S. Turner, K. Patel. The canonical text is published by the RFC Editor.
Abstract
BGPsec-speaking routers are provisioned with private keys in order to sign BGPsec announcements. The corresponding public keys are published in the Global Resource Public Key Infrastructure (RPKI), enabling verification of BGPsec messages. This document describes two methods of generating the public-private key pairs: router-driven and operator-driven.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8635 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8634 BGPsec Router Certificate Rollover
- RFC 8636 Public Key Cryptography for Initial Authentication in Kerberos Algorithm Agility
- RFC 8633 Network Time Protocol Best Current Practices
- RFC 8637 Applicability of the Path Computation Element to the Abstraction and Control of TE Networks
- RFC 8632 A YANG Data Model for Alarm Management
- RFC 8638 IPv4 Multicast over an IPv6 Multicast in Softwire Mesh Networks
- RFC 8631 Link Relation Types for Web Services
- RFC 8639 Subscription to YANG Notifications