RFC 7474: Security Extension for OSPFv2 When Using Manual Key Management
In plain English — editorial summary, not part of the RFC
The current OSPFv2 cryptographic authentication mechanism as defined in RFCs 2328 and 5709 is vulnerable to both inter-session and intra- session replay attacks when using manual keying. Additionally, the existing cryptographic authentication mechanism does not cover the IP header. This omission can be exploited to carry out various types of attacks. This document defines changes to the authentication sequence number mechanism that will protect OSPFv2 from both inter-session and intra- session replay attacks when using manual keys for securing OSPFv2 protocol packets. Additionally, we also describe some changes in the cryptographic hash computation that will eliminate attacks resulting from OSPFv2 not protecting the IP header.
Document record
- Document ID
- RFC7474
- Published
- April 2015
- Authors
- M. Bhatia; S. Hartman; D. Zhang; A. Lindem
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- rtg
- Pages
- 14
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7492Analysis of Bidirectional Forwarding Detection (BFD) Security According to the Keying and Authentication for Routing Protocols (KARP) Design GuidelinesCurrent
March 2015
- RFC 5310IS-IS Generic Cryptographic AuthenticationUpdated
February 2009
- RFC 7416A Security Threat Analysis for the Routing Protocol for Low-Power and Lossy Networks (RPLs)Current
January 2015
- RFC 7353Security Requirements for BGP Path ValidationCurrent
August 2014
- RFC 7183Integrity Protection for the Neighborhood Discovery Protocol (NHDP) and Optimized Link State Routing Protocol Version 2 (OLSRv2)Current
April 2014
- RFC 7182Integrity Check Value and Timestamp TLV Definitions for Mobile Ad Hoc Networks (MANETs)Current
April 2014
- RFC 7138Traffic Engineering Extensions to OSPF for GMPLS Control of Evolving G.709 Optical Transport NetworksCurrent
March 2014
- RFC 7128Resource Public Key Infrastructure (RPKI) Router Implementation ReportCurrent
February 2014
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?