Last Call: <draft-ietf-ospf-security-extension-manual-keying-11.txt> (Security Extension for OSPFv2 when using Manual Key Management) to Proposed Standard

The IESG <> Wed, 11 March 2015 21:15 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id E6BB41A878A; Wed, 11 Mar 2015 14:15:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -101.9
X-Spam-Status: No, score=-101.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, USER_IN_WHITELIST=-100] autolearn=ham
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id 2kiRyHWVF52H; Wed, 11 Mar 2015 14:15:21 -0700 (PDT)
Received: from (localhost [IPv6:::1]) by (Postfix) with ESMTP id 527C81A8748; Wed, 11 Mar 2015 14:15:21 -0700 (PDT)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: The IESG <>
To: IETF-Announce <>
Subject: Last Call: <draft-ietf-ospf-security-extension-manual-keying-11.txt> (Security Extension for OSPFv2 when using Manual Key Management) to Proposed Standard
X-Test-IDTracker: no
X-IETF-IDTracker: 5.12.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <>
Date: Wed, 11 Mar 2015 14:15:21 -0700
Archived-At: <>
X-Mailman-Version: 2.1.15
List-Id: "IETF announcement list. No discussions." <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 11 Mar 2015 21:15:23 -0000

The IESG has approved the following document from the Open Shortest Path 
First IGP WG (ospf):
  'Security Extension for OSPFv2 when using Manual Key Management'
  <draft-ietf-ospf-security-extension-manual-keying-11.txt> as Proposed

However, the document has had substantive changes to section 4 during the final document
review period. These changes are to better align with RFC 7210 and the
best practices in RFC 7211. There is also a correction in the last
paragraph of section 5. Hence, we are going to WG last call the final
document (now RFC 7474) as well as have a simultaneous IETF Last Call on
these specific changes.

The final document is located here:

This diff file shows changes since the last posted version:

This rfcdiff file shows side-by-side changes since the last posted version:

The IESG plans to make a decision in the next few weeks, and solicits
final comments on this action. Please send substantive comments to the mailing lists by 2015-03-25. Exceptionally, comments may be
sent to instead. In either case, please retain the
beginning of the Subject line to allow automated sorting.


   The current OSPFv2 cryptographic authentication mechanism as defined
   in RFC 2328 and RFC 5709 is vulnerable to both inter-session and
   intra-session replay attacks when using manual keying.  Additionally,
   the existing cryptographic authentication mechanism does not cover
   the IP header.  This omission can be exploited to carry out various
   types of attacks.

   This document defines changes to the authentication sequence number
   mechanism that will protect OSPFv2 from both inter-session and intra-
   session replay attacks when using manual keys for securing OSPFv2
   protocol packets.  Additionally, we also describe some changes in the
   cryptographic hash computation that will eliminate attacks resulting
   from OSPFv2 not protecting the IP header.

The file can be obtained via

IESG discussion can be tracked via

No IPR declarations have been submitted directly on this I-D.