%% You should probably cite rfc7474 instead of this I-D. @techreport{ietf-ospf-security-extension-manual-keying-01, number = {draft-ietf-ospf-security-extension-manual-keying-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-ospf-security-extension-manual-keying/01/}, author = {Manav Bhatia and Sam Hartman and Dacheng Zhang and Acee Lindem}, title = {{Security Extension for OSPFv2 when using Manual Key Management}}, pagetotal = 11, year = , month = , day = , abstract = {The current OSPFv2 cryptographic authentication mechanism as defined in the OSPF standards is vulnerable to both inter-session and intra- session replay attacks when its uses manual keying. Additionally, the existing cryptographic authentication schemes do not cover the IP header. This omission can be exploited to carry out various types of attacks. This draft proposes changes to the authentication sequence number mechanism that will protect OSPFv2 from both inter-session and intra- session replay attacks when its using manual keys for securing its protocol packets. Additionally, we also describe some changes in the cryptographic hash computation so that we eliminate most attacks that result because OSPFv2 does not protect the IP header.}, }