This I-D says BGP implementations should be able to be configured with
multiple keys for peers and should do the Intelligent Thing with them.
I just submitted an I-D on TCP-MD5 key change. Until it shows up in the
official repository, see
Here's the abstract:
The TCP-MD5 option is most commonly used to secure
BGP sessions between routers. However, changing
the long-term key is difficult, since the change
needs to be synchronized between different
We describe single-ended strategies that will permit
(mostly) unsynchronized key changes.
--Steven M. Bellovin, http://www.cs.columbia.edu/~smb