TCP MD5 Signature Option

Document Type Replaced Internet-Draft (individual)
Last updated 1996-10-01
Replaced by draft-ietf-idr-bgp-tcp-md5
Stream (None)
Intended RFC status (None)
Expired & archived
pdf htmlized bibtex
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-ietf-idr-bgp-tcp-md5
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This memo describes a TCP extension to enhance security for selected TCP applications. It defines a new TCP option for carrying an MD5 digest in a TCP segment. This digest acts like a signature for that segment, incorporating information known only to the connection end points. Using this option in the way described in this paper significantly reduces the danger from security attacks on critical TCP applications on the Internet. This document specifies an experimental protocol for use in the Internet.


Andy Heffernan (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)