TCP Authentication Option "TCP-AO" Support Nears For The Linux Kernel

Written by Michael Larabel in Linux Networking on 12 September 2023 at 06:00 AM EDT. 16 Comments
LINUX NETWORKING
One of the new Linux networking features we've been looking forward to seeing in the kernel is TCP Authentication Option (TCP-AO / RFC5925) as a means of improving TCP security and authenticity. The eleventh iteration of the TCP-AO patches were posted today for the Linux kernel with it looking like work on this network addition potentially wrapping up soon.

TCP-AO is an upgrade over the existing TCP-MD5 spec for allowing stronger authentication algorithms, improved key management, design considerations for long-lived TCP connections, and related enhancements.

There's been a number of Linux networking subsystem developers working on the TCP-AO support, which is some five thousand lines of new core networking code in the kernel. The v11 patches posted overnight address the last three items brought up during the prior round of code review from mid-August.

TCP-AO RFC


Hopefully soon we'll finall see this TCP-AO support merged into the Linux kernel. Those wishing to learn more about the TCP Authentication Option feature can see the IETF.org RFC5925 spec.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week