OSPF Keychain Authentication

Applications such as OSPF can benefit from a keychain module that provides hitless authentication key rollover, which overcomes the limitation of a static configuration in authentication methods that require manual intervention to change the key periodically.

For each OSPF protocol packet, a key is used to generate and verify a message digest. The key is valid for the duration of the protocol with no option to change the key string or authentication algorithm automatically. The keychain module, which functions as a container for keys with different attributes, allows OSPF to choose the key that best suits its criteria and automatically change the key ID, password, and cryptographic algorithm without manual intervention. OSPFv2 and OSPFv3 authentication using the keychain is configured with the ip ospf authentication keychain or ipv6 ospf authentication keychain commands. For more information on configuring OSPFv2 and OSPFv3 authentication to use the keychain module, refer to the RUCKUS FastIron Layer 3 Routing Configuration Guide.