On Tue, 21 Jul 2026, Paul Wouters wrote:

My last message on this topic. I heard back from some more routing
people on OSPFv3 and AH.

Most major routing vendors had to do AH. In some cases, it was only for
OSPFv3. This was super complex and will likely still have constraints.
It was mandated by the ipv6 propoents (maybe at the times IPsec was still
considered mandatory for IPv6) but it was a huge problem for router
vendors. Then came the auth trailer from the routing people, offering
a simple and matching the operational model for other protocols. Many
but not all AH implementations switched from AH to Auth Trailer.

Some routing people strongly encourage us to deprecate AH to nudge the
last remaining AH users into Auth Trailer.

Paul

Date: Tue, 21 Jul 2026 03:05:29
From: Paul Wouters <[email protected]>
To: "[email protected] WG" <[email protected]>
Subject: [IPsec] Re: On the history of requiring / deprecating AH support

On Mon, 20 Jul 2026, Paul Wouters wrote:

On the part of AH being used for OSPFv3, see:

https://datatracker.ietf.org/doc/html/rfc7166

             Supporting Authentication Trailer for OSPFv3

Abstract

   Currently, OSPF for IPv6 (OSPFv3) uses IPsec as the only mechanism
   for authenticating protocol packets.  This behavior is different from
   authentication mechanisms present in other routing protocols (OSPFv2,
   Intermediate System to Intermediate System (IS-IS), RIP, and Routing
   Information Protocol Next Generation (RIPng)).  In some environments,
   it has been found that IPsec is difficult to configure and maintain
   and thus cannot be used.  This document defines an alternative
   mechanism to authenticate OSPFv3 protocol packets so that OSPFv3 does
   not depend only upon IPsec for authentication.




I am not sure how much this is in use instead of IPsec AH. I am trying
to find out.

Paul

_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]


_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to