Summary

  • A 30 September individual Internet-Draft proposes deprecating IPsec Authentication Header, or AH, for OSPFv3. It advises new implementations not to add AH, permits old implementations to keep it for compatibility, and points operators to ESP with NULL encryption or the existing OSPFv3 Authentication Trailer. It is a proposal, not an approved update to RFC 4552.
  • The draft says routers sharing a link must agree on the authentication mechanism. RFC 7166 separately warns that mismatched authentication parameters can prevent adjacency and that one permissive transition mode may accept unauthenticated packets. Removing an option therefore requires a link-wide continuity and integrity plan, not a one-box toggle.

An operator can turn off a protocol feature on one router in seconds. Its neighbors do not thereby change their expectations. That is the practical seam in draft-acee-lsr-ospfv3-deprecate-ah-00: it proposes retiring AH as an OSPFv3 authentication choice while leaving the routers that exchange OSPFv3 packets to coordinate what replaces it. The Datatracker lists the text as an active individual Internet-Draft with IESG state I-D Exists. The words “Updates: 4552 (if approved)” in its header matter. No RFC has yet been changed by this submission.

The baseline is older and narrower than the new headline might suggest. RFC 4552 already required OSPFv3 implementations conforming to it to support IPsec Encapsulating Security Payload, or ESP, and made AH optional. RFC 7166 already defined an OSPFv3 Authentication Trailer that avoids reliance on IPsec for authentication. The September proposal does not invent either alternative. It would instead discourage new AH implementations, retain existing AH for backward compatibility with an operator-facing deprecation indication, and recommend migration to ESP with NULL encryption or the trailer. Its ESP requirements remain unchanged.

These alternatives are not interchangeable labels for “no security.” ESP with NULL encryption can authenticate and protect integrity without providing confidentiality; NULL describes encryption, not the absence of packet authentication. The trailer is another authentication mechanism, with its own Security Association and key behavior. The draft argues that maintaining a separate AH code path, key configuration and operating procedure adds complexity. It also asserts limited AH adoption, but the inspected text supplies no independent census of installed OSPFv3 networks.

That assertion is the author's rationale, not a measured market share we can report as fact.

The hard part is the shared link. Section 4 of the proposal says an OSPFv3 interface or virtual link uses one authentication mechanism and every router on that link must agree on it. It suggests coordinated configuration and key changes in a maintenance window, or a staged approach only where implementations can accept more than one mechanism during transition. This is not a universal promise of hitless migration. A feature checklist on one chassis cannot establish what a different neighbor will accept, what key material is installed there, or when the adjacency will return after a mismatch.

RFC 7166 makes the risk concrete. In its migration section, a mismatch in Security Association ID, authentication type or message digest can stop an OSPFv3 adjacency from forming. It describes an optional transition mode for introducing the trailer into networks with routers that may not yet authenticate packets. That mode can also accept packets without the trailer; the RFC warns of exposure to unauthenticated data during transition. The mode should not be advertised as an automatic, secure AH-to-trailer bridge. Whether a particular platform can stage AH and another mechanism together is a separate implementation fact requiring verification.

The resulting decision is not simply which modern mechanism to prefer. It is which links still depend on AH, which neighbors must change together, what protection applies at each step, and what evidence will show both packet acceptance and restored adjacency. The draft's security section says neither ESP-NULL nor the trailer protects against a compromised router holding valid keys. Retirement can simplify a supported configuration set; it cannot convert a shared key into proof of a trustworthy neighbor. No inspected source establishes a live migration, incident, vendor readiness or deployed AH share.

Sources