[90875] in North American Network Operators' Group
key change for TCP-MD5
daemon@ATHENA.MIT.EDU (Steven M. Bellovin)
Mon Jun 19 08:33:06 2006
Date: Mon, 19 Jun 2006 08:32:18 -0400
From: "Steven M. Bellovin" <smb@cs.columbia.edu>
To: nanog@nanog.org
Errors-To: owner-nanog@merit.edu
I just submitted an I-D on TCP-MD5 key change. Until it shows up in the
official repository, see
http://www.cs.columbia.edu/~smb/papers/draft-bellovin-keyroll2385-00.txt
Here's the abstract:
The TCP-MD5 option is most commonly used to secure
BGP sessions between routers. However, changing
the long-term key is difficult, since the change
needs to be synchronized between different
organizations.
We describe single-ended strategies that will permit
(mostly) unsynchronized key changes.
Comments welcome.
--Steven M. Bellovin, http://www.cs.columbia.edu/~smb