Using AH for Authentication for OSPFv3

Mukesh Gupta <mgupta@iprg.nokia.com> Tue, 14 May 2002 13:08 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g4ED8ML02980; Tue, 14 May 2002 06:08:22 -0700 (PDT)
Received: by lists.tislabs.com (8.9.1/8.9.1) id IAA00681 Tue, 14 May 2002 08:23:41 -0400 (EDT)
X-mProtect: <200205132325> Nokia Silicon Valley Messaging Protection
Message-ID: <3CE04B50.63529636@iprg.nokia.com>
Date: Mon, 13 May 2002 16:25:04 -0700
From: Mukesh Gupta <mgupta@iprg.nokia.com>
Organization: Nokia
X-Mailer: Mozilla 4.75 [en]C-CCK-MCD {Nokia} (Windows NT 5.0; U)
X-Accept-Language: en
MIME-Version: 1.0
To: ospf@discuss.microsoft.com, ipsec@lists.tislabs.com
Subject: Using AH for Authentication for OSPFv3
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

Hi All,

I am working on providing authentication for OSPFv3 using IPv6 AH
extension header.

RFC 2740 suggests using AH/ESP extension headers of IPv6 for OSPF
authentication but doesn't provide details about how exactly this needs
to be done.

It seems that OSPFv3 shouldn't need to worry about it and it is kernel's
responsibility to provide AH authentication for all OSPFv3 packets. This
way OSPFv3 only receives authenticated packets.

OSPFv3 uses both multicast and unicast packets. Is there any standard
way of handling these packets using IPsec AH ??

Is there any standard way of implementing OSPFv3 Authentication using AH
extension header ?? Is there any vendor out there who has implemented it
??

Comments/Suggestions would be highly appreciated.

regards
Mukesh

--
******************************************************************
Often the best way to win is to forget to keep score.
******************************************************************
Mukesh Gupta
Phone: (650) 625-2264
Cell : (650) 868-9111
http://www.iprg.nokia.com/~mgupta
******************************************************************