Message authentication codes for the Network Time Protocol

Files
draft-ietf-ntp-mac-04.pdf(27.2 KB)
First author draft
Date
DOI
Authors
Malhotra, Aanchal
Goldberg, Sharon
Version
First author draft
OA Version
Citation
A. Malhotra, S. Goldberg. "Message Authentication Codes for the Network Time Protocol."
Abstract
RFC 5905 [RFC5905] states that Network Time Protocol (NTP) packets should be authenticated by appending a 128-bit key to the NTP data, and hashing the result with MD5 to obtain a 128-bit tag. This document deprecates MD5-based authentication, which is considered to be too weak, and recommends the use of AES-CMAC [RFC4493] as a replacement.
Description
License
Copyright (c) 2018 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Simplified BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Simplified BSD License.