Internet Engineering Task Force (IETF) B. Volz
Request for Comments: 8213 Y. Pal
Category: Standards Track Cisco Systems
ISSN: 2070-1721 August 2017
Security of Messages Exchanged between Servers and Relay Agents
Volz & Pal Standards Track [Page 1]
RFC 8213 DHCP Relay/Server Security August 2017
Table of Contents
1. Introduction
The Dynamic Host Configuration Protocol for IPv4 (DHCPv4) [RFC2131] and the Bootstrap Protocol [RFC1542] have no guidance for how to secure messages exchanged between servers and relay agents. The Dynamic Host Configuration Protocol for IPv6 (DHCPv6) [RFC3315] states that IPsec should be used to secure messages exchanged between servers and relay agents but does not recommend encryption. With recent concerns about pervasive monitoring [RFC7258], it is appropriate to require use of IPsec with encryption for relay-to- server communication for DHCPv4 and require use of IPsec with encryption for relay-to-relay and relay-to-server communication for DHCPv6.
Volz & Pal Standards Track [Page 2]
RFC 8213 DHCP Relay/Server Security August 2017 2. Requirements Language and TerminologyThe key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here.
3. Security of Messages Exchanged between Servers and Relay Agents
For DHCPv6 [RFC3315], this specification REQUIRES relay and server implementations to support IPsec encryption of relay-to-relay and relay-to-server communication as documented below. The remainder of this section replaces the text in Section 21.1 of [RFC3315] when this specification is followed.
Volz & Pal Standards Track [Page 3]
RFC 8213 DHCP Relay/Server Security August 2017
Selectors Relay agents are manually configured with the addresses of the relay agent or server to which DHCP messages are to be forwarded. Each relay agent and server that will be using IPsec for securing DHCP messages MUST also be configured with a list of the relay agents to which messages will be returned. The selectors for the relay agents and servers will be the pairs of addresses defining relay agents and servers and the direction of DHCP message exchange on DHCPv4 UDP port 67 or DHCPv6 UDP port 547.
Volz & Pal Standards Track [Page 4]
RFC 8213 DHCP Relay/Server Security August 2017 4. Security ConsiderationsThe security model specified in this document is hop by hop. For DHCPv6, there could be multiple relay agents between a client and server, and each of these hops needs to be secured. For DHCPv4, there is no support for multiple relays.
5. IANA Considerations
This document makes no request of IANA.
Volz & Pal Standards Track [Page 5]
RFC 8213 DHCP Relay/Server Security August 2017 6. References 6.1. Normative References[RFC1542] Wimer, W., "Clarifications and Extensions for the
6.2. Informative References
[CableLabs-DHCP]
Volz & Pal Standards Track [Page 6]
RFC 8213 DHCP Relay/Server Security August 2017
[RFC4107] Bellovin, S. and R. Housley, "Guidelines for Cryptographic
Volz & Pal Standards Track [Page 7]
RFC 8213 DHCP Relay/Server Security August 2017
Acknowledgments