RPKI: Add TCP-MD5 authentication option
RPKI-To-Router (RTR) sessions seem to be similar security-sensitivity as IBGP sessions. BIRD already offered a choice of either "plain TCP" (meh) or "SSH" (secure, albeit a bit more hassle to set up than TCP-MD5). The patch adds TCP-MD5 as another option. TCP-MD5 for RTR is specified through RFC 6810 section 7.3 and RFC 8210 section 9.3. Minor changes by committer.
Showing
- doc/bird.sgml 19 additions, 4 deletionsdoc/bird.sgml
- proto/rpki/config.Y 26 additions, 2 deletionsproto/rpki/config.Y
- proto/rpki/rpki.c 24 additions, 2 deletionsproto/rpki/rpki.c
- proto/rpki/tcp_transport.c 6 additions, 0 deletionsproto/rpki/tcp_transport.c
- proto/rpki/transport.h 8 additions, 1 deletionproto/rpki/transport.h
Loading