Hi sidrops and grow, Forwarding this for awareness — the BGP over TLS/TCP draft just got a revision. The new sections updated may be of interest to these WGs. Happy to discuss here if there's interest.
Thanks, Aravind From: Aravind Babu MahendraBabu (aramahen) <[email protected]> Date: Saturday, 11 July 2026 at 1:56 PM To: [email protected] <[email protected]> Subject: [Idr] BGP over TLS/TCP - draft-wirtgen-bgp-tls-05 - draft update Hi IDR, We've posted -05 of the BGP over TLS/TCP draft: https://datatracker.ietf.org/doc/draft-wirtgen-bgp-tls/05/ Key changes from -04: * Implicit TLS on port 179 — no new port needed. The earlier port allocation request (TBD1) has been withdrawn. BGP reuses port 179 with TCP-AO underneath. * TCP-AO is now mandatory — TLS complements TCP-AO; TCP-AO protects segment integrity; mTLS adds encryption and peer identity. * New sections added: Transport procedures (Section 4) including TLS initiation, failure handling, and what happens when a ClientHello hits a non-TLS peer. Connection/session management (Section 5) covering collision detection with TLS and certificate expiry. Operational considerations (Section 6) defining tls-required, tls-preferred, and ao-only deployment modes. * Mutual TLS (mTLS) with TLS 1.3 explicitly required. * Standards Track — changed from Experimental. * New co-authors: AravindBabu MahendraBabu and Chennakesava Reddy Gaddam (Cisco). * References the draft draft-hbq-bgp-tls-auth for PKI/authentication considerations. We'd appreciate review and feedback, particularly on the Implicit TLS model and the operational deployment modes. Source & issues: https://github.com/IPNetworkingLab/draft-bgp-tls Thanks, Aravind (on behalf of co-authors) From: [email protected] <[email protected]> Date: Monday, 6 July 2026 at 9:46 PM To: Aravind Babu MahendraBabu (aramahen) <[email protected]>; Aravind Babu MahendraBabu (aramahen) <[email protected]>; Chennakesava Reddy Gaddam (chgaddam) <[email protected]>; Chennakesava Reddy Gaddam (chgaddam) <[email protected]>; Olivier Bonaventure <[email protected]>; Olivier Bonaventure <[email protected]>; Thomas Wirtgen <[email protected]> Subject: New Version Notification for draft-wirtgen-bgp-tls-05.txt A new version of Internet-Draft draft-wirtgen-bgp-tls-05.txt has been successfully submitted by Olivier Bonaventure and posted to the IETF repository. Name: draft-wirtgen-bgp-tls Revision: 05 Title: BGP over TLS/TCP Date: 2026-07-06 Group: Individual Submission Pages: 12 URL: https://www.ietf.org/archive/id/draft-wirtgen-bgp-tls-05.txt Status: https://datatracker.ietf.org/doc/draft-wirtgen-bgp-tls/ HTML: https://www.ietf.org/archive/id/draft-wirtgen-bgp-tls-05.html HTMLized: https://datatracker.ietf.org/doc/html/draft-wirtgen-bgp-tls Diff: https://author-tools.ietf.org/iddiff?url2=draft-wirtgen-bgp-tls-05 Abstract: This document specifies the use of TLS over TCP to support BGP. The Border Gateway Protocol (BGP) relies on TCP to establish sessions between routers. While the TCP Authentication Option (TCP-AO) provides transport-layer integrity protection against spoofing and reset attacks, it does not provide confidentiality, cryptographic peer identity, or scalable key management. This document specifies a method for establishing a secure BGP session by running BGP over a TLS 1.3 session. The underlying TCP transport MUST be protected using TCP-AO. An "Implicit TLS" model on TCP port 179 is specified as the preferred mechanism. The IETF Secretariat
_______________________________________________ GROW mailing list -- [email protected] To unsubscribe send an email to [email protected]
