Re: Securing BGP sessions (Issue#41)
Jeff Tantsura <[email protected]> Tue, 10 Dec 2019 16:50:36 -0800
| Newsgroups | gmane.ietf.idr |
|---|---|
| Message-ID | <7e96a2d8-59b2-4c38-a17d-67335a07defd@Spark> |
--===============3400529171439761072== Content-Type: multipart/alternative; boundary="5df03d64_42963e5a_872b" --5df03d64_42963e5a_872b Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline +1 I believe the below clearly represent what has been discussed in Singapor= e. Cheers, Jeff On Dec 10, 2019, 4:34 PM -0800, Mahesh Jethanandani <mjethanandani=40gmai= l.com>, wrote: > This is the second thread in the list of issues that were discussed in = IET=46 106 w.r.t. to BGP YANG model. This particular thread is to discuss= the issue of defining how BGP sessions are going to be secured. > > As stated in Singapore, the model is being defined to secure BGP sessio= ns using > - TCP AO > - TCP MD5 > - IPSec > > In case there was a question of why MD5, it is because there are existi= ng implementations that are choosing to stay with MD5, regardless of the = issues that have been raised about MD5. The model therefore has to suppor= t such implementations. > > The model will use the ietf-key-chain model=E2=80=99s (R=46C 8177) key-= chain-ref to refer to an instance of the key chain. By doing that it will= make use of the key rollover capability defined in that model, and for s= tatic key configuration by setting the end time to infinite in the key ch= ain. The BGP model will leave the case of IPSec as TBD for now, and fill = it when/if the IPSec YANG model is defined. > > Questions/Concerns=3F > > Mahesh Jethanandani > mjethanandani=40gmail.com > > > > =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F > Idr mailing list > Idr=40ietf.org > https://www.ietf.org/mailman/listinfo/idr --5df03d64_42963e5a_872b Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline <html xmlns=3D=22http://www.w3.org/1999/xhtml=22> <head> <title></title> </head> <body> <div name=3D=22messageBodySection=22> <div dir=3D=22auto=22>+1 <div dir=3D=22auto=22><br /></div> <div dir=3D=22auto=22>I believe the below clearly represent what has been= discussed in Singapore.</div> </div> </div> <div name=3D=22messageSignatureSection=22><br /> <div class=3D=22match=46ont=22>Cheers, <div>Jeff</div> </div> </div> <div name=3D=22messageReplySection=22>On Dec 10, 2019, 4:34 PM -0800, Mah= esh Jethanandani <mjethanandani=40gmail.com>, wrote:<br /> <blockquote type=3D=22cite=22 class=3D=22spark=5Fquote=22 style=3D=22marg= in: 5px 5px; padding-left: 10px; border-left: thin solid =231abc9c;=22>Th= is is the second thread in the list of issues that were discussed in IET=46= 106 w.r.t. to BGP YANG model. This particular thread is to discuss the i= ssue of defining how BGP sessions are going to be secured.<br /> <br /> As stated in Singapore, the model is being defined to secure BGP sessions= using<br /> - TCP AO<br /> - TCP MD5<br /> - IPSec<br /> <br /> In case there was a question of why MD5, it is because there are existing= implementations that are choosing to stay with MD5, regardless of the is= sues that have been raised about MD5. The model therefore has to support = such implementations.<br /> <br /> The model will use the ietf-key-chain model=E2=80=99s (R=46C 8177) key-ch= ain-ref to refer to an instance of the key chain. By doing that it will m= ake use of the key rollover capability defined in that model, and for sta= tic key configuration by setting the end time to infinite in the key chai= n. The BGP model will leave the case of IPSec as TBD for now, and fill it= when/if the IPSec YANG model is defined.<br /> <br /> Questions/Concerns=3F<br /> <br /> Mahesh Jethanandani<br /> mjethanandani=40gmail.com<br /> <br /> <br /> <br /> =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F= =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F<br /> Idr mailing list<br /> Idr=40ietf.org<br /> https://www.ietf.org/mailman/listinfo/idr<br /></blockquote> </div> </body> </html> --5df03d64_42963e5a_872b-- --===============3400529171439761072== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Idr mailing list [email protected] https://www.ietf.org/mailman/listinfo/idr --===============3400529171439761072==--