OSPF cryptographic authentication keying

Eastlake III Donald-LDE008 <Donald.Eastlake@MOTOROLA.COM> Tue, 13 August 2002 18:15 UTC

Received: from cherry.ease.lsoft.com (cherry.ease.lsoft.com [209.119.0.109]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA12195 for <ospf-archive@LISTS.IETF.ORG>; Tue, 13 Aug 2002 14:15:06 -0400 (EDT)
Received: from walnut (209.119.0.61) by cherry.ease.lsoft.com (LSMTP for Digital Unix v1.1b) with SMTP id <21.006D2050@cherry.ease.lsoft.com>; Tue, 13 Aug 2002 14:16:23 -0400
Received: from DISCUSS.MICROSOFT.COM by DISCUSS.MICROSOFT.COM (LISTSERV-TCP/IP release 1.8e) with spool id 102793 for OSPF@DISCUSS.MICROSOFT.COM; Tue, 13 Aug 2002 14:16:18 -0400
Received: from 129.188.136.100 by WALNUT.EASE.LSOFT.COM (SMTPL release 1.0f) with TCP; Tue, 13 Aug 2002 14:06:18 -0400
Received: [from pobox4.mot.com (pobox4.mot.com [10.64.251.243]) by motgate.mot.com (motgate 2.1) with ESMTP id LAA00261 for <ospf@discuss.microsoft.com>; Tue, 13 Aug 2002 11:06:22 -0700 (MST)]
Received: [from ma07exm03.corp.isg.mot.com (ma07exm03.corp.isg.mot.com [134.33.90.50]) by pobox4.mot.com (MOT-pobox4 2.0) with ESMTP id LAA28718 for <ospf@discuss.microsoft.com>; Tue, 13 Aug 2002 11:06:21 -0700 (MST)]
Received: by ma07exm03.corp.isg.mot.com with Internet Mail Service (5.5.2654.52) id <QV38AV1Z>; Tue, 13 Aug 2002 14:06:19 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2654.52)
Content-Type: multipart/mixed; boundary="----_=_NextPart_000_01C242F4.1A941140"
Message-ID: <05F679A54DF3D51188100008C7919756D38AED@ma07exm03.corp.isg.mot.com>
Date: Tue, 13 Aug 2002 14:06:10 -0400
Reply-To: Mailing List <OSPF@DISCUSS.MICROSOFT.COM>
Sender: Mailing List <OSPF@DISCUSS.MICROSOFT.COM>
From: Eastlake III Donald-LDE008 <Donald.Eastlake@MOTOROLA.COM>
Subject: OSPF cryptographic authentication keying
To: OSPF@DISCUSS.MICROSOFT.COM
Precedence: list

Hi,

I have a couple of questions about how keying is established for OSPF
cryptographic authentication:

First of all, which may be a stupid questions, I have the impression the
keying is essentially on a pairwise basis, rather than a key being shared
among all the entities in an area. Is that correct?

Second, how are these keys normally established in today's operational
world? I realize this is a bit outside of the scope of OSPF, but do people
use manual entry, SNMP, some negotiation framework like ISAKMP, or what?

Thanks,
Donald

Donald E. Eastlake 3rd, +1-508-851-8280 (voice), +1-508-851-8507 (fax)
Motorola, MS: M2-450, 20 Cabot Boulevard, Mansfield, MA 02048 USA