Everything2
Near Matches
Ignore Exact
Full Text
Everything2

OSPF Security Considerations

created by kessenich

(thing) by kessenich (3.1 y) (print)   ?   (I like it!) Sun Jun 04 2000 at 9:40:24

J. Moy
Request for Comments: 2328
April 1998

All OSPF protocol exchanges are authenticated. OSPF supports multiple types of authentication; the type of authentication in use can be configured on a per network segment basis. One of OSPF's authentication types, namely the Cryptographic authentication option, is believed to be secure against passive attacks and provide significant protection against active attacks. When using the Cryptographic authentication option, each router appends a "message digest" to its transmitted OSPF packets. Receivers then use the shared secret key and received digest to verify that each received OSPF packet is authentic.

The quality of the security provided by the Cryptographic authentication option depends completely on the strength of the message digest algorithm (MD5 is currently the only message digest algorithm specified), the strength of the key being used, and the correct implementation of the security mechanism in all communicating OSPF implementations. It also requires that all parties maintain the secrecy of the shared secret key.

None of the OSPF authentication types provide confidentiality. Nor do they protect against traffic analysis. Key management is also not addressed by this memo.


Copyright (C) The Internet Society (1998). All Rights Reserved.


printable version
chaos

RSA Secret Key Challenge traffic analysis EIGRP OSPF
Cryptography Pix Louisiana Purchase Frequently Used Acronyms at the NSA
RFC Oni packet passive
key confidential Protocol Authentication
algorithm
Y'know, if you log in, you can write something here, or contact authors directly on the site. Create a New User if you don't already have an account.
  Epicenter
Login
Password

password reminder
register

Everything2 Help

Cool Staff Picks
Things you could have written:
So you think you're Bruce Lee
fluid mosaic model
Gargouille
Watching Karen laugh
The New York Deli Experience
Dropped down, pulled out
Undertaker
Everything Professional Career Network
I Enjoy Being a Girl
Internet piracy and the working writer
Dear anonymous. Here is your moment.
Children of the Corny: A Nodermeet Out on the Prairie
Taking Down Large Larry
New Writeups
santo
The Host(review)
LostPsion
"Shut the Fuck Up" Theaters(idea)
Vanish
The line between normal and not(place)
Vanish
insanity(thing)
beatrice
You've been slowly taking me over for nearly a year, do you know that?(idea)
Berek
YouTube(thing)
shaogo
How to Pretend to Have a Job(idea)
hapax
Les Provinciales(review)
zoeb
The Scene(review)
aneurin
Telephone Numbers for drama purposes(idea)
Alnilamski
Cosmicopolis(fiction)
eien_meru
measure(idea)
Dreamvirus
pussy willow(thing)
czeano
Three "T"s(idea)
UncleM
Vantage Point 2: Fractal Thread Count(idea)
E2 is a by-product of the existence of The Everything Development Company