Technical Summary
RFC 4601 mandates the use of IPsec to ensure authentication of the
link-local messages in the Protocol Independent Multicast - Sparse
Mode (PIM-SM) routing protocol. This document specifies mechanisms
to authenticate the PIM-SM link-local messages using the IP security
(IPsec) Encapsulating Security Payload (ESP) or (optionally) the
Authentication Header (AH). It specifies optional mechanisms to
provide confidentiality using the ESP. Manual keying is specified as
the mandatory and default group key management solution. To deal
with issues of scalability and security that exist with manual
keying, an optional support for automated group key management
mechanism is provided. However, the procedures for implementing
automated group key management are left to other documents. This
document updates RFC 4601.
Working Group Summary
Due to limited IPsec expertise in the PIM WG, there was limited
input from the WG on this document.
Document Quality
Two independent implementations are planned for completion in the
second half of 2009.
The document had substantial improvements from a SecDir review by
Brian Weis.
The responsible AD gave a detailed review, and the document has been
updated.
Personnel
Stig Venaas (stig@venaas.com) is the Document Shepherd.
Adrian Farrel (adrian.farrel@huawei.com) is the Responsible AD.