€•wŒsphinx.addnodes”Œdocument”“”)�”}”(Œ rawsource”Œ”Œchildren”]”(Œ translations”Œ LanguagesNode”“”)�”}”(hhh]”(hŒ pending_xref”“”)�”}”(hhh]”Œdocutils.nodes”ŒText”“”ŒChinese (Simplified)”…”�”}”Œparent”hsbaŒ attributes”}”(Œids”]”Œclasses”]”Œnames”]”Œdupnames”]”Œbackrefs”]”Œ refdomain”Œstd”Œreftype”Œdoc”Œ reftarget”Œ%/translations/zh_CN/networking/tcp_ao”Œmodname”NŒ classname”NŒ refexplicit”ˆuŒtagname”hhh ubh)�”}”(hhh]”hŒChinese (Traditional)”…”�”}”hh2sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ%/translations/zh_TW/networking/tcp_ao”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒItalian”…”�”}”hhFsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ%/translations/it_IT/networking/tcp_ao”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒJapanese”…”�”}”hhZsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ%/translations/ja_JP/networking/tcp_ao”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒKorean”…”�”}”hhnsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ%/translations/ko_KR/networking/tcp_ao”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒPortuguese (Brazilian)”…”�”}”hh‚sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ%/translations/pt_BR/networking/tcp_ao”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒSpanish”…”�”}”hh–sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ%/translations/sp_SP/networking/tcp_ao”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubeh}”(h]”h ]”h"]”h$]”h&]”Œcurrent_language”ŒEnglish”uh1h hhŒ _document”hŒsource”NŒline”NubhŒcomment”“”)�”}”(hŒ SPDX-License-Identifier: GPL-2.0”h]”hŒ SPDX-License-Identifier: GPL-2.0”…”�”}”hh·sbah}”(h]”h ]”h"]”h$]”h&]”Œ xml:space”Œpreserve”uh1hµhhh²hh³Œ?/var/lib/git/docbuild/linux/Documentation/networking/tcp_ao.rst”h´KubhŒsection”“”)�”}”(hhh]”(hŒtitle”“”)�”}”(hŒ8TCP Authentication Option Linux implementation (RFC5925)”h]”hŒ8TCP Authentication Option Linux implementation (RFC5925)”…”�”}”(hhÏh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhhÊh²hh³hÇh´KubhŒ paragraph”“”)�”}”(hX�TCP Authentication Option (TCP-AO) provides a TCP extension aimed at verifying segments between trusted peers. It adds a new TCP header option with a Message Authentication Code (MAC). MACs are produced from the content of a TCP segment using a key known to both peers. The intent of TCP-AO is to deprecate TCP-MD5 providing better security, key rotation and support for a variety of MAC algorithms.”h]”hX�TCP Authentication Option (TCP-AO) provides a TCP extension aimed at verifying segments between trusted peers. It adds a new TCP header option with a Message Authentication Code (MAC). MACs are produced from the content of a TCP segment using a key known to both peers. The intent of TCP-AO is to deprecate TCP-MD5 providing better security, key rotation and support for a variety of MAC algorithms.”…”�”}”(hhßh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KhhÊh²hubhÉ)�”}”(hhh]”(hÎ)�”}”(hŒ1. Introduction”h]”hŒ1. Introduction”…”�”}”(hhðh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhhíh²hh³hÇh´KubhŒtable”“”)�”}”(hhh]”(hÎ)�”}”(hŒ2Short and Limited Comparison of TCP-AO and TCP-MD5”h]”hŒ2Short and Limited Comparison of TCP-AO and TCP-MD5”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍh³hÇh´KhjubhŒtgroup”“”)�”}”(hhh]”(hŒcolspec”“”)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”Kuh1jhjubj)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”Kuh1jhjubj)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”Kuh1jhjubhŒthead”“”)�”}”(hhh]”hŒrow”“”)�”}”(hhh]”(hŒentry”“”)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”uh1j@hj=ubjA)�”}”(hhh]”hÞ)�”}”(hŒTCP-MD5”h]”hŒTCP-MD5”…”�”}”(hjNh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KhjKubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj=ubjA)�”}”(hhh]”hÞ)�”}”(hŒTCP-AO”h]”hŒTCP-AO”…”�”}”(hjeh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Khjbubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj=ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj8ubah}”(h]”h ]”h"]”h$]”h&]”uh1j6hjubhŒtbody”“”)�”}”(hhh]”(j<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒSupported MAC algorithms”h]”hŒSupported MAC algorithms”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Khj�ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjŠubjA)�”}”(hhh]”hÞ)�”}”(hŒ,MD5 of data and key (cryptographically weak)”h]”hŒ,MD5 of data and key (cryptographically weak)”…”�”}”(hj§h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Khj¤ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjŠubjA)�”}”(hhh]”hÞ)�”}”(hŒbHMAC-SHA-1-96 and AES-128-CMAC-96. Implementations are permitted to support additional algorithms.”h]”hŒbHMAC-SHA-1-96 and AES-128-CMAC-96. Implementations are permitted to support additional algorithms.”…”�”}”(hj¾h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Khj»ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjŠubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj‡ubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒLength of MACs (bytes)”h]”hŒLength of MACs (bytes)”…”�”}”(hjÞh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KhjÛubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjØubjA)�”}”(hhh]”hÞ)�”}”(hŒ16”h]”hŒ16”…”�”}”(hjõh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Khjòubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjØubjA)�”}”(hhh]”hÞ)�”}”(hŒ~12 for HMAC-SHA-1-96 and AES-128-CMAC-96. Implementations are permitted to support any MAC length that fits in the TCP header.”h]”hŒ~12 for HMAC-SHA-1-96 and AES-128-CMAC-96. Implementations are permitted to support any MAC length that fits in the TCP header.”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Khj ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjØubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj‡ubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒ!Number of keys per TCP connection”h]”hŒ!Number of keys per TCP connection”…”�”}”(hj,h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K#hj)ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj&ubjA)�”}”(hhh]”hÞ)�”}”(hŒ1”h]”hŒ1”…”�”}”(hjCh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K#hj@ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj&ubjA)�”}”(hhh]”hÞ)�”}”(hŒMany”h]”hŒMany”…”�”}”(hjZh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K#hjWubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj&ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj‡ubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒ#Possibility to change an active key”h]”hŒ#Possibility to change an active key”…”�”}”(hjzh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K&hjwubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjtubjA)�”}”(hhh]”hÞ)�”}”(hŒ9Non-practical (both peers have to change them during MSL)”h]”hŒ9Non-practical (both peers have to change them during MSL)”…”�”}”(hj‘h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K&hjŽubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjtubjA)�”}”(hhh]”hÞ)�”}”(hŒSupported by protocol”h]”hŒSupported by protocol”…”�”}”(hj¨h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K&hj¥ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjtubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj‡ubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒ%Protection against ICMP 'hard errors'”h]”hŒ)Protection against ICMP ‘hard errors’”…”�”}”(hjÈh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K*hjÅubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjÂubjA)�”}”(hhh]”hÞ)�”}”(hŒNo”h]”hŒNo”…”�”}”(hjßh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K*hjÜubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjÂubjA)�”}”(hhh]”hÞ)�”}”(hŒ8Yes: ignoring them by default on established connections”h]”hŒ8Yes: ignoring them by default on established connections”…”�”}”(hjöh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K*hjóubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjÂubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj‡ubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒ*Protection against traffic-crossing attack”h]”hŒ*Protection against traffic-crossing attack”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K.hjubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjubjA)�”}”(hhh]”hÞ)�”}”(hŒNo”h]”hŒNo”…”�”}”(hj-h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K.hj*ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjubjA)�”}”(hhh]”hÞ)�”}”(hŒ&Yes: pseudo-header includes TCP ports.”h]”hŒ&Yes: pseudo-header includes TCP ports.”…”�”}”(hjDh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K.hjAubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj‡ubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒ(Protection against replayed TCP segments”h]”hŒ(Protection against replayed TCP segments”…”�”}”(hjdh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K2hjaubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj^ubjA)�”}”(hhh]”hÞ)�”}”(hŒNo”h]”hŒNo”…”�”}”(hj{h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K2hjxubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj^ubjA)�”}”(hhh]”hÞ)�”}”(hŒCSequence Number Extension (SNE) and Initial Sequence Numbers (ISNs)”h]”hŒCSequence Number Extension (SNE) and Initial Sequence Numbers (ISNs)”…”�”}”(hj’h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K2hj�ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj^ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj‡ubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒSupports Connectionless Resets”h]”hŒSupports Connectionless Resets”…”�”}”(hj²h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K7hj¯ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj¬ubjA)�”}”(hhh]”hÞ)�”}”(hŒYes”h]”hŒYes”…”�”}”(hjÉh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K7hjÆubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj¬ubjA)�”}”(hhh]”hÞ)�”}”(hŒ.No. ISNs+SNE are needed to correctly sign RST.”h]”hŒ.No. ISNs+SNE are needed to correctly sign RST.”…”�”}”(hjàh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K7hjÝubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj¬ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj‡ubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒ Standards”h]”hŒ Standards”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K:hjýubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjúubjA)�”}”(hhh]”hÞ)�”}”(hŒRFC 2385”h]”hŒRFC 2385”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K:hjubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjúubjA)�”}”(hhh]”hÞ)�”}”(hŒRFC 5925, RFC 5926”h]”hŒRFC 5925, RFC 5926”…”�”}”(hj.h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K:hj+ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjúubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj‡ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j…hjubeh}”(h]”h ]”h"]”h$]”h&]”Œcols”Kuh1jhjubeh}”(h]”Œid1”ah ]”h"]”h$]”h&]”uh1hþhhíh²hh³hÇh´NubhÉ)�”}”(hhh]”(hÎ)�”}”(hŒ@1.1 Frequently Asked Questions (FAQ) with references to RFC 5925”h]”hŒ@1.1 Frequently Asked Questions (FAQ) with references to RFC 5925”…”�”}”(hj_h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhj\h²hh³hÇh´K?ubhÞ)�”}”(hŒgQ: Can either SendID or RecvID be non-unique for the same 4-tuple (srcaddr, srcport, dstaddr, dstport)?”h]”hŒgQ: Can either SendID or RecvID be non-unique for the same 4-tuple (srcaddr, srcport, dstaddr, dstport)?”…”�”}”(hjmh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KAhj\h²hubhÞ)�”}”(hŒ A: No [3.1]::”h]”hŒ A: No [3.1]:”…”�”}”(hj{h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KDhj\h²hubhŒ literal_block”“”)�”}”(hŒS>> The IDs of MKTs MUST NOT overlap where their TCP connection identifiers overlap.”h]”hŒS>> The IDs of MKTs MUST NOT overlap where their TCP connection identifiers overlap.”…”�”}”hj‹sbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´KFhj\h²hubhÞ)�”}”(hŒBQ: Can Master Key Tuple (MKT) for an active connection be removed?”h]”hŒBQ: Can Master Key Tuple (MKT) for an active connection be removed?”…”�”}”(hj™h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KIhj\h²hubhÞ)�”}”(hŒBA: No, unless it's copied to Transport Control Block (TCB) [3.1]::”h]”hŒCA: No, unless it’s copied to Transport Control Block (TCB) [3.1]:”…”�”}”(hj§h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KKhj\h²hubjŠ)�”}”(hX It is presumed that an MKT affecting a particular connection cannot be destroyed during an active connection -- or, equivalently, that its parameters are copied to an area local to the connection (i.e., instantiated) and so changes would affect only new connections.”h]”hX It is presumed that an MKT affecting a particular connection cannot be destroyed during an active connection -- or, equivalently, that its parameters are copied to an area local to the connection (i.e., instantiated) and so changes would affect only new connections.”…”�”}”hjµsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´KMhj\h²hubhÞ)�”}”(hŒŸQ: If an old MKT needs to be deleted, how should it be done in order to not remove it for an active connection? (As it can be still in use at any moment later)”h]”hŒŸQ: If an old MKT needs to be deleted, how should it be done in order to not remove it for an active connection? (As it can be still in use at any moment later)”…”�”}”(hjÃh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KRhj\h²hubhÞ)�”}”(hŒ†A: Not specified by RFC 5925, seems to be a problem for key management to ensure that no one uses such MKT before trying to remove it.”h]”hŒ†A: Not specified by RFC 5925, seems to be a problem for key management to ensure that no one uses such MKT before trying to remove it.”…”�”}”(hjÑh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KVhj\h²hubhÞ)�”}”(hŒ> A TCP-AO implementation MUST allow for configuration of the behavior of segments with TCP-AO but that do not match an MKT. The initial default of this configuration SHOULD be to silently accept such connections. If this is not the desired case, an MKT can be included to match such connections, or the connection can indicate that TCP-AO is required. Alternately, the configuration can be changed to discard segments with the AO option not matching an MKT.”h]”hXË>> A TCP-AO implementation MUST allow for configuration of the behavior of segments with TCP-AO but that do not match an MKT. The initial default of this configuration SHOULD be to silently accept such connections. If this is not the desired case, an MKT can be included to match such connections, or the connection can indicate that TCP-AO is required. Alternately, the configuration can be changed to discard segments with the AO option not matching an MKT.”…”�”}”hjksbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´K„hj\h²hubhÞ)�”}”(hŒ [10.2.b]::”h]”hŒ [10.2.b]:”…”�”}”(hjyh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KŒhj\h²hubjŠ)�”}”(hŒ¼Connections not matching any MKT do not require TCP-AO. Further, incoming segments with TCP-AO are not discarded solely because they include the option, provided they do not match any MKT.”h]”hŒ¼Connections not matching any MKT do not require TCP-AO. Further, incoming segments with TCP-AO are not discarded solely because they include the option, provided they do not match any MKT.”…”�”}”hj‡sbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´KŽhj\h²hubhÞ)�”}”(hŒ˜Note that Linux TCP-AO implementation differs in this aspect. Currently, TCP-AO segments with unknown key signatures are discarded with warnings logged.”h]”hŒ˜Note that Linux TCP-AO implementation differs in this aspect. Currently, TCP-AO segments with unknown key signatures are discarded with warnings logged.”…”�”}”(hj•h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K’hj\h²hubhÞ)�”}”(hŒŠQ: Does the RFC imply centralized kernel key management in any way? (i.e. that a key on all connections MUST be rotated at the same time?)”h]”hŒŠQ: Does the RFC imply centralized kernel key management in any way? (i.e. that a key on all connections MUST be rotated at the same time?)”…”�”}”(hj£h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K•hj\h²hubhÞ)�”}”(hŒdA: Not specified. MKTs can be managed in userspace, the only relevant part to key changes is [7.3]::”h]”hŒcA: Not specified. MKTs can be managed in userspace, the only relevant part to key changes is [7.3]:”…”�”}”(hj±h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K˜hj\h²hubjŠ)�”}”(hŒd>> All TCP segments MUST be checked against the set of MKTs for matching TCP connection identifiers.”h]”hŒd>> All TCP segments MUST be checked against the set of MKTs for matching TCP connection identifiers.”…”�”}”hj¿sbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´K›hj\h²hubhÞ)�”}”(hŒ_Q: What happens when RNextKeyID requested by a peer is unknown? Should the connection be reset?”h]”hŒ_Q: What happens when RNextKeyID requested by a peer is unknown? Should the connection be reset?”…”�”}”(hjÍh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Kžhj\h²hubhÞ)�”}”(hŒ=A: It should not, no action needs to be performed [7.5.2.e]::”h]”hŒ> An outgoing TCP segment MUST match at most one desired MKT, indicated by the segment’s socket pair. The segment MAY match multiple MKTs, provided that exactly one MKT is indicated as desired. Other information in the segment MAY be used to determine the desired MKT when multiple MKTs match; such information MUST NOT include values in any TCP option fields.”h]”hXSMultiple MKTs may match a single outgoing segment, e.g., when MKTs are being changed. Those MKTs cannot have conflicting IDs (as noted elsewhere), and some mechanism must determine which MKT to use for each given outgoing segment. >> An outgoing TCP segment MUST match at most one desired MKT, indicated by the segment’s socket pair. The segment MAY match multiple MKTs, provided that exactly one MKT is indicated as desired. Other information in the segment MAY be used to determine the desired MKT when multiple MKTs match; such information MUST NOT include values in any TCP option fields.”…”�”}”hjYsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´KÄhj\h²hubhÞ)�”}”(hŒ=Q: Can TCP-MD5 connection migrate to TCP-AO (and vice-versa):”h]”hŒ=Q: Can TCP-MD5 connection migrate to TCP-AO (and vice-versa):”…”�”}”(hjgh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KÏhj\h²hubhÞ)�”}”(hŒ A: No [1]::”h]”hŒ A: No [1]:”…”�”}”(hjuh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KÑhj\h²hubjŠ)�”}”(hŒ TCP MD5-protected connections cannot be migrated to TCP-AO because TCP MD5 does not support any changes to a connection’s security algorithm once established.”h]”hŒ TCP MD5-protected connections cannot be migrated to TCP-AO because TCP MD5 does not support any changes to a connection’s security algorithm once established.”…”�”}”hjƒsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´KÓhj\h²hubhÞ)�”}”(hŒYQ: If all MKTs are removed on a connection, can it become a non-TCP-AO signed connection?”h]”hŒYQ: If all MKTs are removed on a connection, can it become a non-TCP-AO signed connection?”…”�”}”(hj‘h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K×hj\h²hubhÞ)�”}”(hXUA: [7.5.2] doesn't have the same choice as SYN packet handling in [7.5.1.i] that would allow accepting segments without a sign (which would be insecure). While switching to non-TCP-AO connection is not prohibited directly, it seems what the RFC means. Also, there's a requirement for TCP-AO connections to always have one current_key [3.3]::”h]”hXXA: [7.5.2] doesn’t have the same choice as SYN packet handling in [7.5.1.i] that would allow accepting segments without a sign (which would be insecure). While switching to non-TCP-AO connection is not prohibited directly, it seems what the RFC means. Also, there’s a requirement for TCP-AO connections to always have one current_key [3.3]:”…”�”}”(hjŸh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KÚhj\h²hubjŠ)�”}”(hŒGTCP-AO requires that every protected TCP segment match exactly one MKT.”h]”hŒGTCP-AO requires that every protected TCP segment match exactly one MKT.”…”�”}”hj­sbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´Kàhj\h²hubhÞ)�”}”(hŒ[3.3]::”h]”hŒ[3.3]:”…”�”}”(hj»h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Kâhj\h²hubjŠ)�”}”(hŒ�>> An incoming TCP segment including TCP-AO MUST match exactly one MKT, indicated solely by the segment’s socket pair and its TCP-AO KeyID.”h]”hŒ�>> An incoming TCP segment including TCP-AO MUST match exactly one MKT, indicated solely by the segment’s socket pair and its TCP-AO KeyID.”…”�”}”hjÉsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´Kähj\h²hubhÞ)�”}”(hŒ[4.4]::”h]”hŒ[4.4]:”…”�”}”(hj×h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Kçhj\h²hubjŠ)�”}”(hŒPOne or more MKTs. These are the MKTs that match this connection’s socket pair.”h]”hŒPOne or more MKTs. These are the MKTs that match this connection’s socket pair.”…”�”}”hjåsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´Kéhj\h²hubhÞ)�”}”(hŒ;Q: Can a non-TCP-AO connection become a TCP-AO-enabled one?”h]”hŒ;Q: Can a non-TCP-AO connection become a TCP-AO-enabled one?”…”�”}”(hjóh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Kìhj\h²hubhÞ)�”}”(hXA: No: for an already established non-TCP-AO connection it would be impossible to switch to using TCP-AO, as the traffic key generation requires the initial sequence numbers. Paraphrasing, starting using TCP-AO would require re-establishing the TCP connection.”h]”hXA: No: for an already established non-TCP-AO connection it would be impossible to switch to using TCP-AO, as the traffic key generation requires the initial sequence numbers. Paraphrasing, starting using TCP-AO would require re-establishing the TCP connection.”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Kîhj\h²hubeh}”(h]”Œ:frequently-asked-questions-faq-with-references-to-rfc-5925”ah ]”h"]”Œ@1.1 frequently asked questions (faq) with references to rfc 5925”ah$]”h&]”uh1hÈhhíh²hh³hÇh´K?ubeh}”(h]”Œ introduction”ah ]”h"]”Œ1. introduction”ah$]”h&]”uh1hÈhhÊh²hh³hÇh´KubhÉ)�”}”(hhh]”(hÎ)�”}”(hŒ32. In-kernel MKTs database vs database in userspace”h]”hŒ32. In-kernel MKTs database vs database in userspace”…”�”}”(hj"h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhjh²hh³hÇh´KôubhÞ)�”}”(hXSLinux TCP-AO support is implemented using ``setsockopt()s``, in a similar way to TCP-MD5. It means that a userspace application that wants to use TCP-AO should perform ``setsockopt()`` on a TCP socket when it wants to add, remove or rotate MKTs. This approach moves the key management responsibility to userspace as well as decisions on corner cases, i.e. what to do if the peer doesn't respect RNextKeyID; moving more code to userspace, especially responsible for the policy decisions. Besides, it's flexible and scales well (with less locking needed than in the case of an in-kernel database). One also should keep in mind that mainly intended users are BGP processes, not any random applications, which means that compared to IPsec tunnels, no transparency is really needed and modern BGP daemons already have ``setsockopt()s`` for TCP-MD5 support.”h]”(hŒ*Linux TCP-AO support is implemented using ”…”�”}”(hj0h²hh³Nh´NubhŒliteral”“”)�”}”(hŒ``setsockopt()s``”h]”hŒ setsockopt()s”…”�”}”(hj:h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj0ubhŒm, in a similar way to TCP-MD5. It means that a userspace application that wants to use TCP-AO should perform ”…”�”}”(hj0h²hh³Nh´Nubj9)�”}”(hŒ``setsockopt()``”h]”hŒ setsockopt()”…”�”}”(hjLh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj0ubhXy on a TCP socket when it wants to add, remove or rotate MKTs. This approach moves the key management responsibility to userspace as well as decisions on corner cases, i.e. what to do if the peer doesn’t respect RNextKeyID; moving more code to userspace, especially responsible for the policy decisions. Besides, it’s flexible and scales well (with less locking needed than in the case of an in-kernel database). One also should keep in mind that mainly intended users are BGP processes, not any random applications, which means that compared to IPsec tunnels, no transparency is really needed and modern BGP daemons already have ”…”�”}”(hj0h²hh³Nh´Nubj9)�”}”(hŒ``setsockopt()s``”h]”hŒ setsockopt()s”…”�”}”(hj^h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj0ubhŒ for TCP-MD5 support.”…”�”}”(hj0h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Köhjh²hubhÿ)�”}”(hhh]”(hÎ)�”}”(hŒ*Considered pros and cons of the approaches”h]”hŒ*Considered pros and cons of the approaches”…”�”}”(hjyh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍh³hÇh´Mhjvubj)�”}”(hhh]”(j)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”Kuh1jhj‡ubj)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”Kuh1jhj‡ubj)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”Kuh1jhj‡ubj7)�”}”(hhh]”j<)�”}”(hhh]”(jA)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”uh1j@hj«ubjA)�”}”(hhh]”hÞ)�”}”(hŒ``setsockopt()``”h]”j9)�”}”(hj¼h]”hŒ setsockopt()”…”�”}”(hj¾h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjºubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhj·ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj«ubjA)�”}”(hhh]”hÞ)�”}”(hŒ in-kernel DB”h]”hŒ in-kernel DB”…”�”}”(hjÚh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhj×ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj«ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hj¨ubah}”(h]”h ]”h"]”h$]”h&]”uh1j6hj‡ubj†)�”}”(hhh]”(j<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒ Extendability”h]”hŒ Extendability”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhjubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjýubjA)�”}”(hhh]”hÞ)�”}”(hŒ7``setsockopt()`` commands should be extendable syscalls”h]”(j9)�”}”(hŒ``setsockopt()``”h]”hŒ setsockopt()”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjubhŒ' commands should be extendable syscalls”…”�”}”(hjh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhjubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjýubjA)�”}”(hhh]”hÞ)�”}”(hŒ*Netlink messages are simple and extendable”h]”hŒ*Netlink messages are simple and extendable”…”�”}”(hj?h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhj<ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjýubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hjúubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒRequired userspace changes”h]”hŒRequired userspace changes”…”�”}”(hj_h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M hj\ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjYubjA)�”}”(hhh]”hÞ)�”}”(hŒaBGP or any application that wants TCP-AO needs to perform ``setsockopt()s`` and do key management”h]”(hŒ:BGP or any application that wants TCP-AO needs to perform ”…”�”}”(hjvh²hh³Nh´Nubj9)�”}”(hŒ``setsockopt()s``”h]”hŒ setsockopt()s”…”�”}”(hj~h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjvubhŒ and do key management”…”�”}”(hjvh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M hjsubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjYubjA)�”}”(hhh]”hÞ)�”}”(hŒccould be transparent as tunnels, providing something like ``ip tcpao add key`` (delete/show/rotate)”h]”(hŒ:could be transparent as tunnels, providing something like ”…”�”}”(hjŸh²hh³Nh´Nubj9)�”}”(hŒ``ip tcpao add key``”h]”hŒip tcpao add key”…”�”}”(hj§h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjŸubhŒ (delete/show/rotate)”…”�”}”(hjŸh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M hjœubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjYubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hjúubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒMKTs removal or adding”h]”hŒMKTs removal or adding”…”�”}”(hjÑh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MhjÎubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjËubjA)�”}”(hhh]”hÞ)�”}”(hŒharder for userspace”h]”hŒharder for userspace”…”�”}”(hjèh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhjåubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjËubjA)�”}”(hhh]”hÞ)�”}”(hŒharder for kernel”h]”hŒharder for kernel”…”�”}”(hjÿh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhjüubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjËubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hjúubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒ Dump-ability”h]”hŒ Dump-ability”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhj ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj ubjA)�”}”(hhh]”hÞ)�”}”(hŒ``getsockopt()``”h]”j9)�”}”(hj8 h]”hŒ getsockopt()”…”�”}”(hj: h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj6 ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhj3 ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj ubjA)�”}”(hhh]”hÞ)�”}”(hŒNetlink .dump() callback”h]”hŒNetlink .dump() callback”…”�”}”(hjV h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MhjS ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hjúubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒ!Limits on kernel resources/memory”h]”hŒ!Limits on kernel resources/memory”…”�”}”(hjv h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhjs ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hjp ubjA)�”}”(hhh]”hÞ)�”}”(hŒequal”h]”hŒequal”…”�”}”(hj� h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MhjŠ ubah}”(h]”h ]”h"]”h$]”h&]”Œmorecols”Kuh1j@hjp ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hjúubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒ Scalability”h]”hŒ Scalability”…”�”}”(hj® h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhj« ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj¨ ubjA)�”}”(hhh]”hÞ)�”}”(hŒ$contention on ``TCP_LISTEN`` sockets”h]”(hŒcontention on ”…”�”}”(hjÅ h²hh³Nh´Nubj9)�”}”(hŒ``TCP_LISTEN``”h]”hŒ TCP_LISTEN”…”�”}”(hjÍ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjÅ ubhŒ sockets”…”�”}”(hjÅ h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhj ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj¨ ubjA)�”}”(hhh]”hÞ)�”}”(hŒ contention on the whole database”h]”hŒ contention on the whole database”…”�”}”(hjî h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhjë ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj¨ ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hjúubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒMonitoring & warnings”h]”hŒMonitoring & warnings”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhj ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj ubjA)�”}”(hhh]”hÞ)�”}”(hŒ ``TCP_DIAG``”h]”j9)�”}”(hj' h]”hŒTCP_DIAG”…”�”}”(hj) h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj% ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhj" ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj ubjA)�”}”(hhh]”hÞ)�”}”(hŒsame Netlink socket”h]”hŒsame Netlink socket”…”�”}”(hjE h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MhjB ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hjúubj<)�”}”(hhh]”(jA)�”}”(hhh]”hÞ)�”}”(hŒMatching of MKTs”h]”hŒMatching of MKTs”…”�”}”(hje h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhjb ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj_ ubjA)�”}”(hhh]”hÞ)�”}”(hŒ!half-problem: only listen sockets”h]”hŒ!half-problem: only listen sockets”…”�”}”(hj| h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhjy ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj_ ubjA)�”}”(hhh]”hÞ)�”}”(hŒhard”h]”hŒhard”…”�”}”(hj“ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mhj� ubah}”(h]”h ]”h"]”h$]”h&]”uh1j@hj_ ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j;hjúubeh}”(h]”h ]”h"]”h$]”h&]”uh1j…hj‡ubeh}”(h]”h ]”h"]”h$]”h&]”Œcols”Kuh1jhjvubeh}”(h]”Œid2”ah ]”h"]”h$]”h&]”uh1hþhjh²hh³hÇh´Nubeh}”(h]”Œ0in-kernel-mkts-database-vs-database-in-userspace”ah ]”h"]”Œ32. in-kernel mkts database vs database in userspace”ah$]”h&]”uh1hÈhhÊh²hh³hÇh´KôubhÉ)�”}”(hhh]”(hÎ)�”}”(hŒ3. uAPI”h]”hŒ3. uAPI”…”�”}”(hjÌ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhjÉ h²hh³hÇh´M%ubhÞ)�”}”(hX_Linux provides a set of ``setsockopt()s`` and ``getsockopt()s`` that let userspace manage TCP-AO on a per-socket basis. In order to add/delete MKTs ``TCP_AO_ADD_KEY`` and ``TCP_AO_DEL_KEY`` TCP socket options must be used. It is not allowed to add a key on an established non-TCP-AO connection as well as to remove the last key from TCP-AO connection.”h]”(hŒLinux provides a set of ”…”�”}”(hjÚ h²hh³Nh´Nubj9)�”}”(hŒ``setsockopt()s``”h]”hŒ setsockopt()s”…”�”}”(hjâ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjÚ ubhŒ and ”…”�”}”(hjÚ h²hh³Nh´Nubj9)�”}”(hŒ``getsockopt()s``”h]”hŒ getsockopt()s”…”�”}”(hjô h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjÚ ubhŒU that let userspace manage TCP-AO on a per-socket basis. In order to add/delete MKTs ”…”�”}”(hjÚ h²hh³Nh´Nubj9)�”}”(hŒ``TCP_AO_ADD_KEY``”h]”hŒTCP_AO_ADD_KEY”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjÚ ubhŒ and ”…”�”}”hjÚ sbj9)�”}”(hŒ``TCP_AO_DEL_KEY``”h]”hŒTCP_AO_DEL_KEY”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjÚ ubhŒ¢ TCP socket options must be used. It is not allowed to add a key on an established non-TCP-AO connection as well as to remove the last key from TCP-AO connection.”…”�”}”(hjÚ h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M'hjÉ h²hubhÞ)�”}”(hŒÑ``TCP_AO_ADD_KEY`` allows the MAC algorithm and MAC length to be selected. Linux supports the mandatory-to-implement algorithms HMAC-SHA-1-96 and AES-128-CMAC-96. In addition, as Linux extensions, it supports:”h]”(j9)�”}”(hŒ``TCP_AO_ADD_KEY``”h]”hŒTCP_AO_ADD_KEY”…”�”}”(hj4 h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj0 ubhŒ¿ allows the MAC algorithm and MAC length to be selected. Linux supports the mandatory-to-implement algorithms HMAC-SHA-1-96 and AES-128-CMAC-96. In addition, as Linux extensions, it supports:”…”�”}”(hj0 h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M-hjÉ h²hubhŒ bullet_list”“”)�”}”(hhh]”(hŒ list_item”“”)�”}”(hX¬HMAC-SHA256. Linux uses HMAC-SHA256 in the same way as HMAC-SHA1; this includes omitting an explicit entropy extraction step. To work around the missing entropy extraction, users should provide keys with full entropy. The implementation is interoperable with other implementations of HMAC-SHA256 for TCP-AO only when they have implemented the key derivation the same way (and also the same MAC length is selected on each side). ”h]”hÞ)�”}”(hX«HMAC-SHA256. Linux uses HMAC-SHA256 in the same way as HMAC-SHA1; this includes omitting an explicit entropy extraction step. To work around the missing entropy extraction, users should provide keys with full entropy. The implementation is interoperable with other implementations of HMAC-SHA256 for TCP-AO only when they have implemented the key derivation the same way (and also the same MAC length is selected on each side).”h]”hX«HMAC-SHA256. Linux uses HMAC-SHA256 in the same way as HMAC-SHA1; this includes omitting an explicit entropy extraction step. To work around the missing entropy extraction, users should provide keys with full entropy. The implementation is interoperable with other implementations of HMAC-SHA256 for TCP-AO only when they have implemented the key derivation the same way (and also the same MAC length is selected on each side).”…”�”}”(hjW h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M1hjS ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQ hjN h²hh³hÇh´NubjR )�”}”(hŒtAny MAC length for any of the supported MAC algorithms, provided it fits in the TCP header and is at least 4 bytes. ”h]”hÞ)�”}”(hŒsAny MAC length for any of the supported MAC algorithms, provided it fits in the TCP header and is at least 4 bytes.”h]”hŒsAny MAC length for any of the supported MAC algorithms, provided it fits in the TCP header and is at least 4 bytes.”…”�”}”(hjo h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M8hjk ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQ hjN h²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”Œbullet”Œ-”uh1jL h³hÇh´M1hjÉ h²hubhÞ)�”}”(hX``setsockopt(TCP_AO_DEL_KEY)`` command may specify ``tcp_ao_del::current_key`` + ``tcp_ao_del::set_current`` and/or ``tcp_ao_del::rnext`` + ``tcp_ao_del::set_rnext`` which makes such delete "forced": it provides userspace a way to delete a key that's being used and atomically set another one instead. This is not intended for normal use and should be used only when the peer ignores RNextKeyID and keeps requesting/using an old key. It provides a way to force-delete a key that's not trusted but may break the TCP-AO connection.”h]”(j9)�”}”(hŒ``setsockopt(TCP_AO_DEL_KEY)``”h]”hŒsetsockopt(TCP_AO_DEL_KEY)”…”�”}”(hj� h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj‹ ubhŒ command may specify ”…”�”}”(hj‹ h²hh³Nh´Nubj9)�”}”(hŒ``tcp_ao_del::current_key``”h]”hŒtcp_ao_del::current_key”…”�”}”(hj¡ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj‹ ubhŒ + ”…”�”}”(hj‹ h²hh³Nh´Nubj9)�”}”(hŒ``tcp_ao_del::set_current``”h]”hŒtcp_ao_del::set_current”…”�”}”(hj³ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj‹ ubhŒ and/or ”…”�”}”(hj‹ h²hh³Nh´Nubj9)�”}”(hŒ``tcp_ao_del::rnext``”h]”hŒtcp_ao_del::rnext”…”�”}”(hjÅ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj‹ ubhŒ + ”…”�”}”hj‹ sbj9)�”}”(hŒ``tcp_ao_del::set_rnext``”h]”hŒtcp_ao_del::set_rnext”…”�”}”(hj× h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj‹ ubhXt which makes such delete “forcedâ€�: it provides userspace a way to delete a key that’s being used and atomically set another one instead. This is not intended for normal use and should be used only when the peer ignores RNextKeyID and keeps requesting/using an old key. It provides a way to force-delete a key that’s not trusted but may break the TCP-AO connection.”…”�”}”(hj‹ h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M;hjÉ h²hubhÞ)�”}”(hX=The usual/normal key-rotation can be performed with ``setsockopt(TCP_AO_INFO)``. It also provides a uAPI to change per-socket TCP-AO settings, such as ignoring ICMPs, as well as clear per-socket TCP-AO packet counters. The corresponding ``getsockopt(TCP_AO_INFO)`` can be used to get those per-socket TCP-AO settings.”h]”(hŒ4The usual/normal key-rotation can be performed with ”…”�”}”(hjï h²hh³Nh´Nubj9)�”}”(hŒ``setsockopt(TCP_AO_INFO)``”h]”hŒsetsockopt(TCP_AO_INFO)”…”�”}”(hj÷ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjï ubhŒž. It also provides a uAPI to change per-socket TCP-AO settings, such as ignoring ICMPs, as well as clear per-socket TCP-AO packet counters. The corresponding ”…”�”}”(hjï h²hh³Nh´Nubj9)�”}”(hŒ``getsockopt(TCP_AO_INFO)``”h]”hŒgetsockopt(TCP_AO_INFO)”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjï ubhŒ5 can be used to get those per-socket TCP-AO settings.”…”�”}”(hjï h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MDhjÉ h²hubhÞ)�”}”(hŒÝAnother useful command is ``getsockopt(TCP_AO_GET_KEYS)``. One can use it to list all MKTs on a TCP socket or use a filter to get keys for a specific peer and/or sndid/rcvid, VRF L3 interface or get current_key/rnext_key.”h]”(hŒAnother useful command is ”…”�”}”(hj! h²hh³Nh´Nubj9)�”}”(hŒ``getsockopt(TCP_AO_GET_KEYS)``”h]”hŒgetsockopt(TCP_AO_GET_KEYS)”…”�”}”(hj) h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj! ubhŒ¤. One can use it to list all MKTs on a TCP socket or use a filter to get keys for a specific peer and/or sndid/rcvid, VRF L3 interface or get current_key/rnext_key.”…”�”}”(hj! h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MJhjÉ h²hubhÞ)�”}”(hŒ±To repair TCP-AO connections ``setsockopt(TCP_AO_REPAIR)`` is available, provided that the user previously has checkpointed/dumped the socket with ``getsockopt(TCP_AO_REPAIR)``.”h]”(hŒTo repair TCP-AO connections ”…”�”}”(hjA h²hh³Nh´Nubj9)�”}”(hŒ``setsockopt(TCP_AO_REPAIR)``”h]”hŒsetsockopt(TCP_AO_REPAIR)”…”�”}”(hjI h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjA ubhŒY is available, provided that the user previously has checkpointed/dumped the socket with ”…”�”}”(hjA h²hh³Nh´Nubj9)�”}”(hŒ``getsockopt(TCP_AO_REPAIR)``”h]”hŒgetsockopt(TCP_AO_REPAIR)”…”�”}”(hj[ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjA ubhŒ.”…”�”}”(hjA h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MNhjÉ h²hubhÞ)�”}”(hŒÃA tip here for scaled TCP_LISTEN sockets, that may have some thousands TCP-AO keys, is: use filters in ``getsockopt(TCP_AO_GET_KEYS)`` and asynchronous delete with ``setsockopt(TCP_AO_DEL_KEY)``.”h]”(hŒgA tip here for scaled TCP_LISTEN sockets, that may have some thousands TCP-AO keys, is: use filters in ”…”�”}”(hjs h²hh³Nh´Nubj9)�”}”(hŒ``getsockopt(TCP_AO_GET_KEYS)``”h]”hŒgetsockopt(TCP_AO_GET_KEYS)”…”�”}”(hj{ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjs ubhŒ and asynchronous delete with ”…”�”}”(hjs h²hh³Nh´Nubj9)�”}”(hŒ``setsockopt(TCP_AO_DEL_KEY)``”h]”hŒsetsockopt(TCP_AO_DEL_KEY)”…”�”}”(hj� h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjs ubhŒ.”…”�”}”(hjs h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MRhjÉ h²hubhÞ)�”}”(hX×Linux TCP-AO also provides a bunch of segment counters that can be helpful with troubleshooting/debugging issues. Every MKT has good/bad counters that reflect how many packets passed/failed verification. Each TCP-AO socket has the following counters: - for good segments (properly signed) - for bad segments (failed TCP-AO verification) - for segments with unknown keys - for segments where an AO signature was expected, but wasn't found - for the number of ignored ICMPs”h]”hXÙLinux TCP-AO also provides a bunch of segment counters that can be helpful with troubleshooting/debugging issues. Every MKT has good/bad counters that reflect how many packets passed/failed verification. Each TCP-AO socket has the following counters: - for good segments (properly signed) - for bad segments (failed TCP-AO verification) - for segments with unknown keys - for segments where an AO signature was expected, but wasn’t found - for the number of ignored ICMPs”…”�”}”(hj¥ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MVhjÉ h²hubhÞ)�”}”(hŒÄTCP-AO per-socket counters are also duplicated with per-netns counters, exposed with SNMP. Those are ``TCPAOGood``, ``TCPAOBad``, ``TCPAOKeyNotFound``, ``TCPAORequired`` and ``TCPAODroppedIcmps``.”h]”(hŒeTCP-AO per-socket counters are also duplicated with per-netns counters, exposed with SNMP. Those are ”…”�”}”(hj³ h²hh³Nh´Nubj9)�”}”(hŒ ``TCPAOGood``”h]”hŒ TCPAOGood”…”�”}”(hj» h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj³ ubhŒ, ”…”�”}”(hj³ h²hh³Nh´Nubj9)�”}”(hŒ ``TCPAOBad``”h]”hŒTCPAOBad”…”�”}”(hjÍ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj³ ubhŒ, ”…”�”}”hj³ sbj9)�”}”(hŒ``TCPAOKeyNotFound``”h]”hŒTCPAOKeyNotFound”…”�”}”(hjß h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj³ ubhŒ, ”…”�”}”(hj³ h²hh³Nh´Nubj9)�”}”(hŒ``TCPAORequired``”h]”hŒ TCPAORequired”…”�”}”(hjñ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj³ ubhŒ and ”…”�”}”(hj³ h²hh³Nh´Nubj9)�”}”(hŒ``TCPAODroppedIcmps``”h]”hŒTCPAODroppedIcmps”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj³ ubhŒ.”…”�”}”(hj³ h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M`hjÉ h²hubhÞ)�”}”(hXXFor monitoring purposes, there are following TCP-AO trace events: ``tcp_hash_bad_header``, ``tcp_hash_ao_required``, ``tcp_ao_handshake_failure``, ``tcp_ao_wrong_maclen``, ``tcp_ao_wrong_maclen``, ``tcp_ao_key_not_found``, ``tcp_ao_rnext_request``, ``tcp_ao_synack_no_key``, ``tcp_ao_snd_sne_update``, ``tcp_ao_rcv_sne_update``. It's possible to separately enable any of them and one can filter them by net-namespace, 4-tuple, family, L3 index, and TCP header flags. If a segment has a TCP-AO header, the filters may also include keyid, rnext, and maclen. SNE updates include the rolled-over numbers.”h]”(hŒBFor monitoring purposes, there are following TCP-AO trace events: ”…”�”}”(hj h²hh³Nh´Nubj9)�”}”(hŒ``tcp_hash_bad_header``”h]”hŒtcp_hash_bad_header”…”�”}”(hj# h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj ubhŒ, ”…”�”}”(hj h²hh³Nh´Nubj9)�”}”(hŒ``tcp_hash_ao_required``”h]”hŒtcp_hash_ao_required”…”�”}”(hj5 h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj ubhŒ, ”…”�”}”hj sbj9)�”}”(hŒ``tcp_ao_handshake_failure``”h]”hŒtcp_ao_handshake_failure”…”�”}”(hjG h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj ubhŒ, ”…”�”}”(hj h²hh³Nh´Nubj9)�”}”(hŒ``tcp_ao_wrong_maclen``”h]”hŒtcp_ao_wrong_maclen”…”�”}”(hjY h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj ubhŒ, ”…”�”}”hj sbj9)�”}”(hŒ``tcp_ao_wrong_maclen``”h]”hŒtcp_ao_wrong_maclen”…”�”}”(hjk h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj ubhŒ, ”…”�”}”hj sbj9)�”}”(hŒ``tcp_ao_key_not_found``”h]”hŒtcp_ao_key_not_found”…”�”}”(hj} h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj ubhŒ, ”…”�”}”hj sbj9)�”}”(hŒ``tcp_ao_rnext_request``”h]”hŒtcp_ao_rnext_request”…”�”}”(hj� h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj ubhŒ, ”…”�”}”hj sbj9)�”}”(hŒ``tcp_ao_synack_no_key``”h]”hŒtcp_ao_synack_no_key”…”�”}”(hj¡ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj ubhŒ, ”…”�”}”hj sbj9)�”}”(hŒ``tcp_ao_snd_sne_update``”h]”hŒtcp_ao_snd_sne_update”…”�”}”(hj³ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj ubhŒ, ”…”�”}”hj sbj9)�”}”(hŒ``tcp_ao_rcv_sne_update``”h]”hŒtcp_ao_rcv_sne_update”…”�”}”(hjÅ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj ubhX. It’s possible to separately enable any of them and one can filter them by net-namespace, 4-tuple, family, L3 index, and TCP header flags. If a segment has a TCP-AO header, the filters may also include keyid, rnext, and maclen. SNE updates include the rolled-over numbers.”…”�”}”(hj h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MdhjÉ h²hubhÞ)�”}”(hŒQRFC 5925 very permissively specifies how TCP port matching can be done for MKTs::”h]”hŒPRFC 5925 very permissively specifies how TCP port matching can be done for MKTs:”…”�”}”(hjÝ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MmhjÉ h²hubjŠ)�”}”(hXTCP connection identifier. A TCP socket pair, i.e., a local IP address, a remote IP address, a TCP local port, and a TCP remote port. Values can be partially specified using ranges (e.g., 2-30), masks (e.g., 0xF0), wildcards (e.g., "*"), or any other suitable indication.”h]”hXTCP connection identifier. A TCP socket pair, i.e., a local IP address, a remote IP address, a TCP local port, and a TCP remote port. Values can be partially specified using ranges (e.g., 2-30), masks (e.g., 0xF0), wildcards (e.g., "*"), or any other suitable indication.”…”�”}”hjë sbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j‰h³hÇh´MphjÉ h²hubhÞ)�”}”(hŒžCurrently Linux TCP-AO implementation doesn't provide any TCP port matching. Probably, port ranges are the most flexible for uAPI, but so far not implemented.”h]”hŒ Currently Linux TCP-AO implementation doesn’t provide any TCP port matching. Probably, port ranges are the most flexible for uAPI, but so far not implemented.”…”�”}”(hjù h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MuhjÉ h²hubeh}”(h]”Œuapi”ah ]”h"]”Œ3. uapi”ah$]”h&]”uh1hÈhhÊh²hh³hÇh´M%ubhÉ)�”}”(hhh]”(hÎ)�”}”(hŒ(4. ``setsockopt()`` vs ``accept()`` race”h]”(hŒ4. ”…”�”}”(hjh²hh³Nh´Nubj9)�”}”(hŒ``setsockopt()``”h]”hŒ setsockopt()”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjubhŒ vs ”…”�”}”(hjh²hh³Nh´Nubj9)�”}”(hŒ ``accept()``”h]”hŒaccept()”…”�”}”(hj,h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjubhŒ race”…”�”}”(hjh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÍhjh²hh³hÇh´MzubhÞ)�”}”(hXÆIn contrast with an established TCP-MD5 connection which has just one key, TCP-AO connections may have many keys, which means that accepted connections on a listen socket may have any amount of keys as well. As copying all those keys on a first properly signed SYN would make the request socket bigger, that would be undesirable. Currently, the implementation doesn't copy keys to request sockets, but rather look them up on the "parent" listener socket.”h]”hXÌIn contrast with an established TCP-MD5 connection which has just one key, TCP-AO connections may have many keys, which means that accepted connections on a listen socket may have any amount of keys as well. As copying all those keys on a first properly signed SYN would make the request socket bigger, that would be undesirable. Currently, the implementation doesn’t copy keys to request sockets, but rather look them up on the “parentâ€� listener socket.”…”�”}”(hjDh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M|hjh²hubhÞ)�”}”(hŒûThe result is that when userspace removes TCP-AO keys, that may break not-yet-established connections on request sockets as well as not removing keys from sockets that were already established, but not yet ``accept()``'ed, hanging in the accept queue.”h]”(hŒÎThe result is that when userspace removes TCP-AO keys, that may break not-yet-established connections on request sockets as well as not removing keys from sockets that were already established, but not yet ”…”�”}”(hjRh²hh³Nh´Nubj9)�”}”(hŒ ``accept()``”h]”hŒaccept()”…”�”}”(hjZh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjRubhŒ#’ed, hanging in the accept queue.”…”�”}”(hjRh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mƒhjh²hubhÞ)�”}”(hŒŸThe reverse is valid as well: if userspace adds a new key for a peer on a listener socket, the established sockets in the accept queue won't have the new keys.”h]”hŒ¡The reverse is valid as well: if userspace adds a new key for a peer on a listener socket, the established sockets in the accept queue won’t have the new keys.”…”�”}”(hjrh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´Mˆhjh²hubhÞ)�”}”(hX•At this moment, the resolution for the two races: ``setsockopt(TCP_AO_ADD_KEY)`` vs ``accept()`` and ``setsockopt(TCP_AO_DEL_KEY)`` vs ``accept()`` is delegated to userspace. This means that it's expected that userspace would check the MKTs on the socket that was returned by ``accept()`` to verify that any key rotation that happened on the listen socket is reflected on the newly established connection.”h]”(hŒ2At this moment, the resolution for the two races: ”…”�”}”(hj€h²hh³Nh´Nubj9)�”}”(hŒ``setsockopt(TCP_AO_ADD_KEY)``”h]”hŒsetsockopt(TCP_AO_ADD_KEY)”…”�”}”(hjˆh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj€ubhŒ vs ”…”�”}”(hj€h²hh³Nh´Nubj9)�”}”(hŒ ``accept()``”h]”hŒaccept()”…”�”}”(hjšh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj€ubhŒ and ”…”�”}”(hj€h²hh³Nh´Nubj9)�”}”(hŒ``setsockopt(TCP_AO_DEL_KEY)``”h]”hŒsetsockopt(TCP_AO_DEL_KEY)”…”�”}”(hj¬h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj€ubhŒ vs ”…”�”}”hj€sbj9)�”}”(hŒ ``accept()``”h]”hŒaccept()”…”�”}”(hj¾h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj€ubhŒƒ is delegated to userspace. This means that it’s expected that userspace would check the MKTs on the socket that was returned by ”…”�”}”(hj€h²hh³Nh´Nubj9)�”}”(hŒ ``accept()``”h]”hŒaccept()”…”�”}”(hjÐh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hj€ubhŒu to verify that any key rotation that happened on the listen socket is reflected on the newly established connection.”…”�”}”(hj€h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MŒhjh²hubhÞ)�”}”(hŒŸThis is a similar "do-nothing" approach to TCP-MD5 from the kernel side and may be changed later by introducing new flags to ``tcp_ao_add`` and ``tcp_ao_del``.”h]”(hŒ�This is a similar “do-nothingâ€� approach to TCP-MD5 from the kernel side and may be changed later by introducing new flags to ”…”�”}”(hjèh²hh³Nh´Nubj9)�”}”(hŒ``tcp_ao_add``”h]”hŒ tcp_ao_add”…”�”}”(hjðh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjèubhŒ and ”…”�”}”(hjèh²hh³Nh´Nubj9)�”}”(hŒ``tcp_ao_del``”h]”hŒ tcp_ao_del”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j8hjèubhŒ.”…”�”}”(hjèh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M“hjh²hubhÞ)�”}”(hŒ}Note that this race is rare for it needs TCP-AO key rotation to happen during the 3-way handshake for the new TCP connection.”h]”hŒ}Note that this race is rare for it needs TCP-AO key rotation to happen during the 3-way handshake for the new TCP connection.”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M—hjh²hubeh}”(h]”Œsetsockopt-vs-accept-race”ah ]”h"]”Œ 4. setsockopt() vs accept() race”ah$]”h&]”uh1hÈhhÊh²hh³hÇh´MzubhÉ)�”}”(hhh]”(hÎ)�”}”(hŒ5. Interaction with TCP-MD5”h]”hŒ5. Interaction with TCP-MD5”…”�”}”(hj3h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhj0h²hh³hÇh´M›ubhÞ)�”}”(hŒ°A TCP connection can not migrate between TCP-AO and TCP-MD5 options. The established sockets that have either AO or MD5 keys are restricted for adding keys of the other option.”h]”hŒ°A TCP connection can not migrate between TCP-AO and TCP-MD5 options. The established sockets that have either AO or MD5 keys are restricted for adding keys of the other option.”…”�”}”(hjAh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M�hj0h²hubhÞ)�”}”(hXFor listening sockets the picture is different: BGP server may want to receive both TCP-AO and (deprecated) TCP-MD5 clients. As a result, both types of keys may be added to TCP_CLOSED or TCP_LISTEN sockets. It's not allowed to add different types of keys for the same peer.”h]”hXFor listening sockets the picture is different: BGP server may want to receive both TCP-AO and (deprecated) TCP-MD5 clients. As a result, both types of keys may be added to TCP_CLOSED or TCP_LISTEN sockets. It’s not allowed to add different types of keys for the same peer.”…”�”}”(hjOh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M¡hj0h²hubeh}”(h]”Œinteraction-with-tcp-md5”ah ]”h"]”Œ5. interaction with tcp-md5”ah$]”h&]”uh1hÈhhÊh²hh³hÇh´M›ubhÉ)�”}”(hhh]”(hÎ)�”}”(hŒ6. SNE Linux implementation”h]”hŒ6. SNE Linux implementation”…”�”}”(hjhh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhjeh²hh³hÇh´M§ubhÞ)�”}”(hX%RFC 5925 [6.2] describes the algorithm of how to extend TCP sequence numbers with SNE. In short: TCP has to track the previous sequence numbers and set sne_flag when the current SEQ number rolls over. The flag is cleared when both current and previous SEQ numbers cross 0x7fff, which is 32Kb.”h]”hX%RFC 5925 [6.2] describes the algorithm of how to extend TCP sequence numbers with SNE. In short: TCP has to track the previous sequence numbers and set sne_flag when the current SEQ number rolls over. The flag is cleared when both current and previous SEQ numbers cross 0x7fff, which is 32Kb.”…”�”}”(hjvh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M©hjeh²hubhÞ)�”}”(hXIn times when sne_flag is set, the algorithm compares SEQ for each packet with 0x7fff and if it's higher than 32Kb, it assumes that the packet should be verified with SNE before the increment. As a result, there's this [0; 32Kb] window, when packets with (SNE - 1) can be accepted.”h]”hXIn times when sne_flag is set, the algorithm compares SEQ for each packet with 0x7fff and if it’s higher than 32Kb, it assumes that the packet should be verified with SNE before the increment. As a result, there’s this [0; 32Kb] window, when packets with (SNE - 1) can be accepted.”…”�”}”(hj„h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M®hjeh²hubhÞ)�”}”(hXmLinux implementation simplifies this a bit: as the network stack already tracks the first SEQ byte that ACK is wanted for (snd_una) and the next SEQ byte that is wanted (rcv_nxt) - that's enough information for a rough estimation on where in the 4GB SEQ number space both sender and receiver are. When they roll over to zero, the corresponding SNE gets incremented.”•X"h]”hXoLinux implementation simplifies this a bit: as the network stack already tracks the first SEQ byte that ACK is wanted for (snd_una) and the next SEQ byte that is wanted (rcv_nxt) - that’s enough information for a rough estimation on where in the 4GB SEQ number space both sender and receiver are. When they roll over to zero, the corresponding SNE gets incremented.”…”�”}”(hj’h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M³hjeh²hubhÞ)�”}”(hX1tcp_ao_compute_sne() is called for each TCP-AO segment. It compares SEQ numbers from the segment with snd_una or rcv_nxt and fits the result into a 2GB window around them, detecting SEQ numbers rolling over. That simplifies the code a lot and only requires SNE numbers to be stored on every TCP-AO socket.”h]”hX1tcp_ao_compute_sne() is called for each TCP-AO segment. It compares SEQ numbers from the segment with snd_una or rcv_nxt and fits the result into a 2GB window around them, detecting SEQ numbers rolling over. That simplifies the code a lot and only requires SNE numbers to be stored on every TCP-AO socket.”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M¹hjeh²hubhÞ)�”}”(hX½The 2GB window at first glance seems much more permissive compared to RFC 5926. But that is only used to pick the correct SNE before/after a rollover. It allows more TCP segment replays, but yet all regular TCP checks in tcp_sequence() are applied on the verified segment. So, it trades a bit more permissive acceptance of replayed/retransmitted segments for the simplicity of the algorithm and what seems better behaviour for large TCP windows.”h]”hX½The 2GB window at first glance seems much more permissive compared to RFC 5926. But that is only used to pick the correct SNE before/after a rollover. It allows more TCP segment replays, but yet all regular TCP checks in tcp_sequence() are applied on the verified segment. So, it trades a bit more permissive acceptance of replayed/retransmitted segments for the simplicity of the algorithm and what seems better behaviour for large TCP windows.”…”�”}”(hj®h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´M¾hjeh²hubeh}”(h]”Œsne-linux-implementation”ah ]”h"]”Œ6. sne linux implementation”ah$]”h&]”uh1hÈhhÊh²hh³hÇh´M§ubhÉ)�”}”(hhh]”(hÎ)�”}”(hŒ7. Links”h]”hŒ7. Links”…”�”}”(hjÇh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhjÄh²hh³hÇh´MÇubhŒdefinition_list”“”)�”}”(hhh]”(hŒdefinition_list_item”“”)�”}”(hŒ]RFC 5925 The TCP Authentication Option https://www.rfc-editor.org/rfc/pdfrfc/rfc5925.txt.pdf ”h]”(hŒterm”“”)�”}”(hŒ&RFC 5925 The TCP Authentication Option”h]”hŒ&RFC 5925 The TCP Authentication Option”…”�”}”(hjâh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jàh³hÇh´MÊhjÜubhŒ definition”“”)�”}”(hhh]”hÞ)�”}”(hŒ5https://www.rfc-editor.org/rfc/pdfrfc/rfc5925.txt.pdf”h]”hŒ reference”“”)�”}”(hj÷h]”hŒ5https://www.rfc-editor.org/rfc/pdfrfc/rfc5925.txt.pdf”…”�”}”(hjûh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”Œrefuri”j÷uh1jùhjõubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MÊhjòubah}”(h]”h ]”h"]”h$]”h&]”uh1jðhjÜubeh}”(h]”h ]”h"]”h$]”h&]”uh1jÚh³hÇh´MÊhj×ubjÛ)�”}”(hŒƒRFC 5926 Cryptographic Algorithms for the TCP Authentication Option (TCP-AO) https://www.rfc-editor.org/rfc/pdfrfc/rfc5926.txt.pdf ”h]”(já)�”}”(hŒLRFC 5926 Cryptographic Algorithms for the TCP Authentication Option (TCP-AO)”h]”hŒLRFC 5926 Cryptographic Algorithms for the TCP Authentication Option (TCP-AO)”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jàh³hÇh´MÍhjubjñ)�”}”(hhh]”hÞ)�”}”(hŒ5https://www.rfc-editor.org/rfc/pdfrfc/rfc5926.txt.pdf”h]”jú)�”}”(hj2h]”hŒ5https://www.rfc-editor.org/rfc/pdfrfc/rfc5926.txt.pdf”…”�”}”(hj4h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”Œrefuri”j2uh1jùhj0ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MÍhj-ubah}”(h]”h ]”h"]”h$]”h&]”uh1jðhjubeh}”(h]”h ]”h"]”h$]”h&]”uh1jÚh³hÇh´MÍhj×h²hubjÛ)�”}”(hŒ�Draft "SHA-2 Algorithm for the TCP Authentication Option (TCP-AO)" https://datatracker.ietf.org/doc/html/draft-nayak-tcp-sha2-03 ”h]”(já)�”}”(hŒBDraft "SHA-2 Algorithm for the TCP Authentication Option (TCP-AO)"”h]”hŒFDraft “SHA-2 Algorithm for the TCP Authentication Option (TCP-AO)â€�”…”�”}”(hjXh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jàh³hÇh´MÐhjTubjñ)�”}”(hhh]”hÞ)�”}”(hŒ=https://datatracker.ietf.org/doc/html/draft-nayak-tcp-sha2-03”h]”jú)�”}”(hjkh]”hŒ=https://datatracker.ietf.org/doc/html/draft-nayak-tcp-sha2-03”…”�”}”(hjmh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”Œrefuri”jkuh1jùhjiubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MÐhjfubah}”(h]”h ]”h"]”h$]”h&]”uh1jðhjTubeh}”(h]”h ]”h"]”h$]”h&]”uh1jÚh³hÇh´MÐhj×h²hubjÛ)�”}”(hŒ{RFC 2385 Protection of BGP Sessions via the TCP MD5 Signature Option https://www.rfc-editor.org/rfc/pdfrfc/rfc2385.txt.pdf ”h]”(já)�”}”(hŒDRFC 2385 Protection of BGP Sessions via the TCP MD5 Signature Option”h]”hŒDRFC 2385 Protection of BGP Sessions via the TCP MD5 Signature Option”…”�”}”(hj‘h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jàh³hÇh´MÓhj�ubjñ)�”}”(hhh]”hÞ)�”}”(hŒ5https://www.rfc-editor.org/rfc/pdfrfc/rfc2385.txt.pdf”h]”jú)�”}”(hj¤h]”hŒ5https://www.rfc-editor.org/rfc/pdfrfc/rfc2385.txt.pdf”…”�”}”(hj¦h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”Œrefuri”j¤uh1jùhj¢ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MÓhjŸubah}”(h]”h ]”h"]”h$]”h&]”uh1jðhj�ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jÚh³hÇh´MÓhj×h²hubeh}”(h]”h ]”h"]”h$]”h&]”uh1jÕhjÄh²hh³hÇh´NubhŒ field_list”“”)�”}”(hhh]”hŒfield”“”)�”}”(hhh]”(hŒ field_name”“”)�”}”(hŒAuthor”h]”hŒAuthor”…”�”}”(hjØh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÖhjÓh³hÇh´KubhŒ field_body”“”)�”}”(hŒ Dmitry Safonov ”h]”hÞ)�”}”(hjêh]”(hŒDmitry Safonov <”…”�”}”(hjìh²hh³Nh´Nubjú)�”}”(hŒdima@arista.com”h]”hŒdima@arista.com”…”�”}”(hjóh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”Œrefuri”Œmailto:dima@arista.com”uh1jùhjìubhŒ>”…”�”}”(hjìh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´MÕhjèubah}”(h]”h ]”h"]”h$]”h&]”uh1jæhjÓubeh}”(h]”h ]”h"]”h$]”h&]”uh1jÑh³hÇh´MÕhjÎh²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jÌhjÄh²hh³hÇh´MÕubeh}”(h]”Œlinks”ah ]”h"]”Œ7. links”ah$]”h&]”uh1hÈhhÊh²hh³hÇh´MÇubeh}”(h]”Œ6tcp-authentication-option-linux-implementation-rfc5925”ah ]”h"]”Œ8tcp authentication option linux implementation (rfc5925)”ah$]”h&]”uh1hÈhhh²hh³hÇh´Kubeh}”(h]”h ]”h"]”h$]”h&]”Œsource”hÇuh1hŒcurrent_source”NŒ current_line”NŒsettings”Œdocutils.frontend”ŒValues”“”)�”}”(hÍNŒ generator”NŒ datestamp”NŒ source_link”NŒ source_url”NŒ toc_backlinks”j@Œfootnote_backlinks”KŒ sectnum_xform”KŒstrip_comments”NŒstrip_elements_with_classes”NŒ strip_classes”NŒ report_level”KŒ halt_level”KŒexit_status_level”KŒdebug”NŒwarning_stream”NŒ traceback”ˆŒinput_encoding”Œ utf-8-sig”Œinput_encoding_error_handler”Œstrict”Œoutput_encoding”Œutf-8”Œoutput_encoding_error_handler”jQŒerror_encoding”Œutf-8”Œerror_encoding_error_handler”Œbackslashreplace”Œ language_code”Œen”Œrecord_dependencies”NŒconfig”NŒ id_prefix”hŒauto_id_prefix”Œid”Œ dump_settings”NŒdump_internals”NŒdump_transforms”NŒdump_pseudo_xml”NŒexpose_internals”NŒstrict_visitor”NŒ_disable_config”NŒ_source”hÇŒ _destination”NŒ _config_files”]”Œ7/var/lib/git/docbuild/linux/Documentation/docutils.conf”aŒfile_insertion_enabled”ˆŒ raw_enabled”KŒline_length_limit”M'Œpep_references”NŒ pep_base_url”Œhttps://peps.python.org/”Œpep_file_url_template”Œpep-%04d”Œrfc_references”NŒ rfc_base_url”Œ&https://datatracker.ietf.org/doc/html/”Œ tab_width”KŒtrim_footnote_reference_space”‰Œsyntax_highlight”Œlong”Œ smart_quotes”ˆŒsmartquotes_locales”]”Œcharacter_level_inline_markup”‰Œdoctitle_xform”‰Œ docinfo_xform”KŒsectsubtitle_xform”‰Œ image_loading”Œlink”Œembed_stylesheet”‰Œcloak_email_addresses”ˆŒsection_self_link”‰Œenv”NubŒreporter”NŒindirect_targets”]”Œsubstitution_defs”}”Œsubstitution_names”}”Œrefnames”}”Œrefids”}”Œnameids”}”(j,j)jjjjjÆ jà j j j-j*jbj_jÁj¾j$j!uŒ nametypes”}”(j,‰j‰j‰jÆ ‰j ‰j-‰jb‰jÁ‰j$‰uh}”(j)hÊjhíjj\jà jj jÉ j*jj_j0j¾jej!jÄjWjj¼ jvuŒ footnote_refs”}”Œ citation_refs”}”Œ autofootnotes”]”Œautofootnote_refs”]”Œsymbol_footnotes”]”Œsymbol_footnote_refs”]”Œ footnotes”]”Œ citations”]”Œautofootnote_start”KŒsymbol_footnote_start”KŒ id_counter”Œ collections”ŒCounter”“”}”j_Ks…”R”Œparse_messages”]”Œtransform_messages”]”Œ transformer”NŒ include_log”]”Œ decoration”Nh²hub.