@techreport{liu-ospfv3-automated-keying-req-01, number = {draft-liu-ospfv3-automated-keying-req-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-liu-ospfv3-automated-keying-req/01/}, author = {Ya Liu}, title = {{OSPFv3 Automated Group Keying Requirements}}, pagetotal = 15, year = 2007, month = jul, day = 10, abstract = {RFC4552 describes how to provide authentication/confidentiality to OSPFv3 using IPsec. It specifies that same IPsec SA parameters be configured for both inbound and outbound SAs to provide the "one to many" security for multicast OSPFv3 communications over broadcast links (e.g., Ethernet). Manual keying is specified as the mandatory and default group key management solution. However, issues of scalability and security exist with manual keying. It is better to replace manual keying with automated group key management. This document discusses the requirements on OSPFv3 automated group key management, assuming that the centralized group key management architecture introduced in {[}RFC4046{]} is used.}, }