nanog mailing list archives

Re: AH is pretty useless and perhaps should be deprecated


From: Bill Fehring <lists () billfehring com>
Date: Sun, 15 Nov 2009 21:29:58 -0800

On Sun, Nov 15, 2009 at 20:48, Joel Jaeggli <joelja () bogus com> wrote:
Owen DeLong wrote:
I've never seen anyone use AH vs. ESP.

OSPFv3?

Maybe I'm asking a dumb question, but why would one prefer AH over ESP
for OSPFv3?

RFC4552:
"In order to provide authentication to OSPFv3, implementations MUST
support ESP and MAY support AH."

-Bill


Current thread: