I-D Action: draft-cassen-vrrp-auth-hmac-01.txt
[email protected] Mon, 27 Jul 2026 03:01:45 -0700
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178514650547.1120088.1615653210481400013@dt-datatracker-d4d6ff9d9-ql5mb> |
Internet-Draft draft-cassen-vrrp-auth-hmac-01.txt is now available.
Title: An HMAC Authentication Extension for the Virtual Router Redundancy Protocol (VRRP)
Authors: Alexandre Cassen
Quentin Armitage
Name: draft-cassen-vrrp-auth-hmac-01.txt
Pages: 18
Dates: 2026-07-27
Abstract:
VRRP relies on a hop limit of 255 to prove that an advertisement came
from the local link. That guard cannot apply when advertisements
travel as multi-hop unicast across a routed or overlay network, as is
common in cloud deployments, leaving the protocol open to off-segment
injection and replay. The legacy VRRPv2 authentication types do not
close this gap and were removed from later VRRP specifications. This
document defines an authentication extension that appends an HMAC-
SHA256 trailer and a time-based sequence number to VRRPv3
advertisements, authenticating the sender as a holder of the group
key, protecting message integrity and bounding replay, for both IP
address families. The extension is the primary defense where the
hop-limit check cannot apply, and defense in depth for multicast and
single-hop unicast, where that check remains in force.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-cassen-vrrp-auth-hmac/
There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-cassen-vrrp-auth-hmac-01
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-cassen-vrrp-auth-hmac-01
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]