Hi sidrops and grow,

Forwarding this for awareness — the BGP over TLS/TCP draft just got a revision. 
The new sections updated may be of interest to these WGs. Happy to discuss here 
if there's interest.

Thanks,
Aravind
From: Aravind Babu MahendraBabu (aramahen) <[email protected]>
Date: Saturday, 11 July 2026 at 1:56 PM
To: [email protected] <[email protected]>
Subject: [Idr] BGP over TLS/TCP - draft-wirtgen-bgp-tls-05 - draft update

Hi IDR,

We've posted -05 of the BGP over TLS/TCP draft:
https://datatracker.ietf.org/doc/draft-wirtgen-bgp-tls/05/

Key changes from -04:


  *
Implicit TLS on port 179 — no new port needed. The earlier port allocation 
request (TBD1) has been withdrawn. BGP reuses port 179 with TCP-AO underneath.
  *
TCP-AO is now mandatory — TLS complements TCP-AO; TCP-AO protects segment 
integrity; mTLS adds encryption and peer identity.
  *
New sections added: Transport procedures (Section 4) including TLS initiation, 
failure handling, and what happens when a ClientHello hits a non-TLS peer. 
Connection/session management (Section 5) covering collision detection with TLS 
and certificate expiry. Operational considerations (Section 6) defining 
tls-required, tls-preferred, and ao-only deployment modes.
  *
Mutual TLS (mTLS) with TLS 1.3 explicitly required.
  *
Standards Track — changed from Experimental.
  *
New co-authors: AravindBabu MahendraBabu and Chennakesava Reddy Gaddam (Cisco).
  *
References the draft draft-hbq-bgp-tls-auth for PKI/authentication 
considerations.

We'd appreciate review and feedback, particularly on the Implicit TLS model and 
the operational deployment modes.
Source & issues: https://github.com/IPNetworkingLab/draft-bgp-tls

Thanks,
Aravind (on behalf of co-authors)

From: [email protected] <[email protected]>
Date: Monday, 6 July 2026 at 9:46 PM
To: Aravind Babu MahendraBabu (aramahen) <[email protected]>; Aravind Babu 
MahendraBabu (aramahen) <[email protected]>; Chennakesava Reddy Gaddam 
(chgaddam) <[email protected]>; Chennakesava Reddy Gaddam (chgaddam) 
<[email protected]>; Olivier Bonaventure <[email protected]>; 
Olivier Bonaventure <[email protected]>; Thomas Wirtgen 
<[email protected]>
Subject: New Version Notification for draft-wirtgen-bgp-tls-05.txt

A new version of Internet-Draft draft-wirtgen-bgp-tls-05.txt has been
successfully submitted by Olivier Bonaventure and posted to the
IETF repository.

Name:     draft-wirtgen-bgp-tls
Revision: 05
Title:    BGP over TLS/TCP
Date:     2026-07-06
Group:    Individual Submission
Pages:    12
URL:      https://www.ietf.org/archive/id/draft-wirtgen-bgp-tls-05.txt
Status:   https://datatracker.ietf.org/doc/draft-wirtgen-bgp-tls/
HTML:     https://www.ietf.org/archive/id/draft-wirtgen-bgp-tls-05.html
HTMLized: https://datatracker.ietf.org/doc/html/draft-wirtgen-bgp-tls
Diff:     https://author-tools.ietf.org/iddiff?url2=draft-wirtgen-bgp-tls-05

Abstract:

   This document specifies the use of TLS over TCP to support BGP.  The
   Border Gateway Protocol (BGP) relies on TCP to establish sessions
   between routers.  While the TCP Authentication Option (TCP-AO)
   provides transport-layer integrity protection against spoofing and
   reset attacks, it does not provide confidentiality, cryptographic
   peer identity, or scalable key management.  This document specifies a
   method for establishing a secure BGP session by running BGP over a
   TLS 1.3 session.  The underlying TCP transport MUST be protected
   using TCP-AO.  An "Implicit TLS" model on TCP port 179 is specified
   as the preferred mechanism.



The IETF Secretariat


_______________________________________________
GROW mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to