Archives by Category
Contact
- Hagen Paul Pfeifer
- http://jauu.net
- hagen@jauu.net (encrypted preferred)
- KeyId: 0x98350C22
- Telephone: +49 174 5455209
Follow this blog
IETF: TCP Authentication Option
- Published in: ietf
- | Time: 01:51:05 CEST
- | SHA1: f04c9f38cd00b25ee685ea252458abbfe5924c85
Just now, two new Request for Comments are now online available:
- RFC 5925 – The TCP Authentication Option
- RFC 5926 – Cryptographic Algorithms for the TCP Authentication Option (TCP-AO)
These two standards (and probably upcomming enhancements in several years ;) are the replacement for TCP MD5 Option (RFC 2385). TCP-AO specifies stronger Message Authentication Codes to protect against replay attacks for long lived connections like BGP sessions. It is a generic contaier where other authentication codes can be used. Several other aspects are adjusted too like an extended sequence number mechanism (imaginable as shadow registers) and IPv6 support.
Florian Westphal and I held a presentation where we mentioned TCP-AO at that time upcoming standard: Trends und Neuerungen bei der Protokollentwicklung
The Internet is now a more safer place … ;)