LDP Hello Cryptographic Authentication (RFC7349) Disclosure Number: IPCOM000238306D
Publication Date: 2014-Aug-15
Document File: 28 page(s) / 32K

The Label Distribution Protocol (LDP) [RFC5036] sets up LDP sessions that run between LDP peers. The peers could either be directly connected at the link level or be multiple hops away. An LDP Label Switching Router (LSR) could either be configured with the identity of its peers or could discover them using LDP Hello messages. These messages are sent encapsulated in UDP addressed to "all routers on this subnet" or to a specific IP address. Periodic Hello messages are also used to maintain the relationship between LDP peers necessary to keep the LDP session active.

Internet Engineering Task Force (IETF)                          L. Zheng Request for Comments: 7349                                       M. Chen Category: Standards Track                            Huawei Technologies ISSN: 2070-1721                                                M. Bhatia                                                           Ionos Networks                                                              August 2014

                  LDP Hello Cryptographic Authentication


   This document introduces a new optional Cryptographic Authentication    TLV that LDP can use to secure its Hello messages.  It secures the    Hello messages against spoofing attacks and some well-known attacks    against the IP header.  This document describes a mechanism to secure    the LDP Hello messages using Hashed Message Authentication Code    (HMAC) with the National Institute of Standards and Technology (NIST)    Secure Hash Standard family of algorithms.

 RFC 7349         LDP Hello Cryptographic Authentication      August 2014

 Table of Contents

   1.  Introduction  . . . . . . . . . . . . . . . . . . . . . . . .   2

     1.1.  Requirements Language . . . . . . . . . . . . . . . . . .   3

   2.  Cryptogra...