netsec-sig - Re: [Security-WG] I2 - MD5/TCP-AO Discussion Paper, draft
Subject: Internet2 Network Security SIG
List archive
- From: Steven Wallace <>
- To:
- Subject: Re: [Security-WG] I2 - MD5/TCP-AO Discussion Paper, draft
- Date: Thu, 30 Mar 2017 13:41:32 -0400
- Ironport-phdr: 9a23:S33w3BX9KlPytfOM7Uaknnxvg9zV8LGtZVwlr6E/grcLSJyIuqrYbBKAt8tkgFKBZ4jH8fUM07OQ6PG9HzxRqs/Y7DgrS99lb1c9k8IYnggtUoauKHbQC7rUVRE8B9lIT1R//nu2YgB/Ecf6YEDO8DXptWZBUhrwOhBoKevrB4Xck9q41/yo+53Ufg5EmCexbal8IRiyrQjdrMobjI9tJqos1xfErWZDdvhLy29vOV+dhQv36N2q/J5k/SRQuvYh+NBFXK7nYak2TqFWASo/PWwt68LlqRfMTQ2U5nsBSWoWiQZHAxLE7B7hQJj8tDbxu/dn1ymbOc32Sq00WSin4qx2RhLklDsLOjgk+2zRl8d+jr9UoAi5qhJ/34Hbb5ybOvRwfq3Df9wURm1PU91eVyBdB4OxdYsPA/YDMOtesoLzp0EOrRy7BQS0Ge3v1iFHhmHo0q08zu8uERvJ3AgkH90UrHvbssj+OaAJUeCuwqjF1jTDb+5M1Tjj9YfIbwksrPeRVrx+dsrRzFMgFwLDjliIq4zlIjWV1uUVs2eF9epsT+SvhHA7qw1pozivwNsshZfThoIT1F/E6Tt1zJwrKtKlVU53ecWrEIFXty6GLYR5X90tT3t0tyY9z70KoZ+7czYWyJQp3RLfbOaHc4eQ7h3/VeaROit3hHV/dL2jgBay9FCsxfHiWcmuzFZGtC1FksPDtn0Lyhfd6dCHR+Ng8kqu3TuDzR3f5+BELEwuiKbWJZEszqQxm5cXqUjPAyD7lUHsgKOLd0go5vKk5/r6brjlvJORN4l5gRzkPKs0gMywG+E4PxAOX2eF/eS806Xu/UjjT7VLiv06j7DVsJbEKsUVvKK5DBVV0oAk6xmjFTum0ckYkWMZI11YZRKLl4npO1fQL/DkFfqznluhnTNxy/zbP7DsAo/BImXNnbruZ7pw6kpRxBI2zd9F5pJUDr8BIOj0Wk/0rNHYFQQ5MgKvzubmFdVxzJ0RVn+SAqOBKqPdrUeI5v4zI+mLfIIVoyjyJOQ45/70jH85hV8ccbCn3JsYc324GvVmI16FYXr3nNsNC2YKvgwiTOP0kl2CVyBcZ2qsU64m+D40FZ+mXs//QdW2jbecxianD9hJaUhHDEyBC3Hla9/CVvsROwyIJco0qSAJS7WnA7Ao0RWnvwKyn6F8McLV52sVuY+1h4s93PHaiRxnrW88NM+ayWzYF2w=
I’m always looking for fewer words. How about the following: It’s good practice to authenticate BGP sessions. The traditional method for authenticating BGP sessions relies on MD5. MD5 is considered a weak algorithm, and its use should be depreccated as practical. TCP-AO is a newer and more secure BGP authentication method, however vendor support for TCP-AO isn’t robust. It’s recommended that all BGP sessions (including point-to-point) be authenticated. While MD5 is weak, it still provides an important level of protection. BGP authentication should move to TCP-AO as it become practicable.
|
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- [Security-WG] I2 - MD5/TCP-AO Discussion Paper, draft, gcbrowni, 03/30/2017
- Re: [Security-WG] I2 - MD5/TCP-AO Discussion Paper, draft, Steven Wallace, 03/30/2017
- Re: [Security-WG] I2 - MD5/TCP-AO Discussion Paper, draft, Andrew Gallo, 03/30/2017
- Re: [Security-WG] I2 - MD5/TCP-AO Discussion Paper, draft, Andrew Gallo, 03/30/2017
- Re: [Security-WG] I2 - MD5/TCP-AO Discussion Paper, draft, Michael H Lambert, 03/30/2017
- Re: [Security-WG] I2 - MD5/TCP-AO Discussion Paper, draft, David Farmer, 03/30/2017
- Re: [Security-WG] I2 - MD5/TCP-AO Discussion Paper, draft, gcbrowni, 03/31/2017
- Re: [Security-WG] I2 - MD5/TCP-AO Discussion Paper, draft, David Farmer, 03/30/2017
Archive powered by MHonArc 2.6.19.