Re: [bess] Secdir last call review of draft-ietf-bess-evpn-optimized-ir-09

"Rabadan, Jorge (Nokia - US/Mountain View)" <jorge.rabadan@nokia.com> Wed, 17 November 2021 09:07 UTC

Return-Path: <jorge.rabadan@nokia.com>
X-Original-To: bess@ietfa.amsl.com
Delivered-To: bess@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 589AF3A0B30; Wed, 17 Nov 2021 01:07:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level:
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.701, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nokia.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Oy03z8EM-rux; Wed, 17 Nov 2021 01:07:08 -0800 (PST)
Received: from NAM10-DM6-obe.outbound.protection.outlook.com (mail-dm6nam10on2107.outbound.protection.outlook.com [40.107.93.107]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 90E573A00C8; Wed, 17 Nov 2021 01:07:08 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=kkTLTP0KkfjBRSA+anLAdqOBWF3GAk69Ejq1DEg26lIQzUv1x+Jikt78+BpnOejFdzAJ1U0CgpQOCRPg4VRphRskmpn+7o9vUZgxYiPHI8+j0RJoAbLncuC+DDPrXTpXAiWO8NH9Zz3D+lWPPvuF898MqJTXQYOJmiIS7VSTWubC/N8wKfR7ZFxC+DgZR2KssPt4IoKpJkDhTeGHjrwbpA5nU/F74xD33dEP+jNAx7iTJHHKf0Xy79XwnDvzRtr+2CHN+pL0ERUpus5j1Yw8Lw6ddo2TpClJdhi8wv7KBgHWrYrblPHeJ8CBflXu049Jtt1WanelRFDS5cQEDsr7Jg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=myzcfQSyjpw3DsBdDO7cxwX6MbphGVzWRUbipcmAFKs=; b=dwOIXfokAKDgxqMDwPhDqELyhC7gO1IST8F9oqFP9o1x2Jp8UrdBaLIQLN2bmsjQddsDFXcBFHkq81U2VS0zDhsI4631LZNcdmR5NTa/NMcgWGggKHBU/3KoApKbOB/1qorZCn1FRCGo2+aHOsHEKxpAiqq2IV+TzhbAxJ8Um7CRbOnqnGZY5xbZdb3MZoQnXfd6h2NHIL9gfbw/A4Ov5atgCvP0Lbo4h/1EK51X9OO91IaArulPtO2idDrxtvH6iNioWY2YywV5psrXjoeyxx6LEVOY1ZxH+Awe8BvNWRB/L4qYfR+9yzFSZd/IMgaPI2fxnfwTgKl5sA+a6lXqyg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nokia.com; dmarc=pass action=none header.from=nokia.com; dkim=pass header.d=nokia.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nokia.onmicrosoft.com; s=selector1-nokia-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=myzcfQSyjpw3DsBdDO7cxwX6MbphGVzWRUbipcmAFKs=; b=BzkEaIqBJM+9HJqr7IZkgPGItCGQLNwfgItmA4NnhphwZ+pjUm0CNlLZLMk4nJGr2G178WAcrvWu0aEAt7+wKbaYYqEn3rAlNjRKkwYLP4/w4DwYiT9uzYAFHifldq61e1ZygvnWlsDhRw/DR1gRQsFyqj77Qeiq6kLphpUMtHs=
Received: from BY3PR08MB7060.namprd08.prod.outlook.com (2603:10b6:a03:36d::19) by BYAPR08MB3896.namprd08.prod.outlook.com (2603:10b6:a02:84::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4690.16; Wed, 17 Nov 2021 09:07:05 +0000
Received: from BY3PR08MB7060.namprd08.prod.outlook.com ([fe80::c481:f856:9121:e]) by BY3PR08MB7060.namprd08.prod.outlook.com ([fe80::c481:f856:9121:e%7]) with mapi id 15.20.4669.022; Wed, 17 Nov 2021 09:07:05 +0000
From: "Rabadan, Jorge (Nokia - US/Mountain View)" <jorge.rabadan@nokia.com>
To: Derek Atkins <derek@ihtfp.com>, "secdir@ietf.org" <secdir@ietf.org>
CC: "bess@ietf.org" <bess@ietf.org>, "draft-ietf-bess-evpn-optimized-ir.all@ietf.org" <draft-ietf-bess-evpn-optimized-ir.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>
Thread-Topic: Secdir last call review of draft-ietf-bess-evpn-optimized-ir-09
Thread-Index: AQHXu3pZWBnJ1VT/ukeJa8VALCENH6wAL4hr
Date: Wed, 17 Nov 2021 09:07:05 +0000
Message-ID: <BY3PR08MB7060E2DD04FE114DEEE3F681F7959@BY3PR08MB7060.namprd08.prod.outlook.com>
References: <163361121039.16337.12285140758441545338@ietfa.amsl.com>
In-Reply-To: <163361121039.16337.12285140758441545338@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nokia.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 28ae01f9-1cb7-4f08-edf1-08d9a9a9a04a
x-ms-traffictypediagnostic: BYAPR08MB3896:
x-microsoft-antispam-prvs: <BYAPR08MB3896E14137142809522FAA42F79A9@BYAPR08MB3896.namprd08.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: Bb4WTo0RjdSc3b21YpUl5TcLSQ1FPV5l393W0K3nMHxiiwUUNR5Odo3yzDD8oHG0rU+PzgHVSIiD9Dt+1ObGiKw+TCrf5HY0XtrztX6yeguNNsaiwHTztMerkGkBfm2QAb8iCZ+X/2LEm30/aU6K0LReT2Yrh4wkm6vfhxr8VsFeyDFXCPnZYPwNb/2DD38cvDvU1SO8MSEMf1MJg0KHE8p9vclinXv5nuej2HoDQUqtnehY0kMMP5HAck0aBd34PSWqt7pI47rIw0yR4MXhIeSAzA+8SaW6Qshfx1PQS4leTQC4B/mQogHeC1pOUOpWs3837LVPyUoIp49B4EdvzH2+7IAUleqzMuLjUktNLt8zDPV98TDDzdrSK8M+GKsyJFqOY3TEJwy3UtXRbobh4d79cwgsQpqeUv2E5p54xdikpcaOH4BlxdeNrvHU/2vXcyD2sYb0fVpcjBuzk/T891AYk1pkoUPQpL1iLs8aJUzk0ceTLgt4xKtdEkHwIogeFwv1ccp2R5vPRLsL42RhbjTTI7bvtes/tT6dIeIm4Rf7Xo3wZ3AFab5lveuq2KVUFjECH5rI6A2G5N7HLI+2O8Gbqm3b1AUrwOdx4cJ3ihV7ny13bmSEhDxmYNwTVWRBexEEIfShrBgBXI2oS6zmJD+3LgPWYG+MOpZ9rziZvjyPZLaWZpwqPWzHreFjx8r81BLym9Gu9J/grDtIHxEXWg==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BY3PR08MB7060.namprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(76116006)(26005)(66476007)(55016002)(86362001)(66946007)(91956017)(83380400001)(186003)(66446008)(8936002)(82960400001)(33656002)(71200400001)(66556008)(122000001)(38100700002)(7696005)(9326002)(64756008)(508600001)(52536014)(4326008)(2906002)(53546011)(5660300002)(110136005)(6506007)(316002)(38070700005)(54906003)(8676002)(9686003); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: VAiEtsdJKqbEU9oZAaBeNxQN8wyHOrKU8vLxX9kn4PAPrvFMw1l1oA65ciDo+zegeu3SHkSFfUM/iI5RcOv3ib9xhG62vvYDLg2x2DMPW75VbXz7HCOP8k3EyNzEJ1gt32m/weZM2n7hIgPZtDPYIHgrTn90M7p8xW15gFZoCq69G0082BgwmU5DFPvvUEy+x0axvQvhHQ6lVJpADAOHOo/RVXByRDrnhdEHrUhF+tVAV3pDu16jBCyhfPk5hltw840+11tMGB7WN5uDYQy5T2kdRYbxh8z4WRcSumIDHYodwv+sOFHhYjzQv4rfDGS0CJG01UvPQpRrBMZaBRQ3K7LzpFw+8UUvCeIX67UAY9AYMmPED4p7d/7j8tTcCwYtNx9cK8/P6zBXz3BWlTrKXLsCSWDUCOg64uI5Kk0a4zC8O/zs4oa28j/EG5sd9PPdp+JX2WpQZqRqcLJVdw4SNGwqveT18hyWBU9YmuTx5pC9FHMPYGvq4YHyLBjXi+to9TN27xEKQn8oAxxR3Puqu6T1fmF6SPSxcUlqfPmjZ6yUidEMmnIUSkXlCKHprkLfQWnsa5sMuycsFFqJvZJ8G+qTARTteufgMXY571i4L6CJBtBouA75/QsxNPzHvJvSXdXgdtQpjdlq8UCqKEyZ3PDa7WuAcW6inEtCoTdhMlfraaxEDyj1ogxBrbd/njqkJVNlqXcU95PlpglSfUfmczp0+OFSVz7RIF0ocDVZlpjRWAzzjCXkzu8r57FMNQ8nsvbZqscRZsf5NZPFlYaux5oxABXkLYZJKh63ynIdSFttiEtMhKaE/PQo94uTjTCGg3hHYbz0/QcP5gpTIGa5I6MNJkIYfxj8+COyvbLpWm349+YflYLTr9ORBFdupLhWBB3f04FtIuSfW+wd8hRZ4QPa8FwY4v6tz154XQTOQZ2+G+MyGj45qt4Xcy/NitIDDKKD00pCyH8KYODFOh4Vlyd/y60ANsNVnA9ibG5rOdFhp5WkWowHzpzc1PC3kpFEx/pD/PtkrUPfkLeEklgNtGYHFTaiNinSQmopISxSvsWnT8Sql11Km+X1wtwaKCz1LkWIXunrmcd5+eTc7bD5/cYmO8TKTeX6QByM3H7zq0oVjjZFf4RQigLlVfZZ6ZCOVXdL1AeZCfjFgASCgyKraypdL626yzfNONScx9bxR3pNwy4ADYOnfxTgQsfdajtGqlGxYA1cWkj2rEZ8n6Arirl+r+JW7OCyPY2U8xqKriD7mo3d7tdlIQZV/RiLWvip/Vc70gUVEU/fO6cIxB+0CaNKgl7bRjQSksgDleiBbYKOqLpdVOHxhWFPPlcqGr3Z4/xIAn8LuyWc0DGRJxK3OdH2TPjwgIhteGsw0Nn/zF26qDUeuL07HcZujBymDGukmRDBkI5Q9Mn4u71fKAtcl2VtHorTLxqLdde6cDAwG5N/jQv+iUlcPHM7Uh0e3KTKd1gPvJKOXX06ZtmdSVo2YsmJ9SpxCQif38j7EkCdLxYmM2dq0r6qGKQv179iLMOGlT7P701iog/fNI9FLIeUYkssFa32CK++sYI8TgOVh24mjQ5dQG17jsnDpDRgRaBeTvQXxSPRrpGYk1LwjliWj11vFKGL0kL73vuwT7Pnx6HML4A+6Ygmz5svlKNHqmS0
Content-Type: multipart/alternative; boundary="_000_BY3PR08MB7060E2DD04FE114DEEE3F681F7959BY3PR08MB7060namp_"
MIME-Version: 1.0
X-OriginatorOrg: nokia.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BY3PR08MB7060.namprd08.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 28ae01f9-1cb7-4f08-edf1-08d9a9a9a04a
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Nov 2021 09:07:05.1486 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5d471751-9675-428d-917b-70f44f9630b0
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: GcKyoAWSpW3/x7lzAtn19W7SWeTb0SXRuvg3cAZwzMEXWrG8KaeZO16gVGfaccKhunhpodJMTG7P+WEVLkq03Q==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR08MB3896
Archived-At: <https://mailarchive.ietf.org/arch/msg/bess/8wVFvFP5vxJFU-_CCMqZWa03ito>
Subject: Re: [bess] Secdir last call review of draft-ietf-bess-evpn-optimized-ir-09
X-BeenThere: bess@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: BGP-Enabled ServiceS working group discussion list <bess.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/bess>, <mailto:bess-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bess/>
List-Post: <mailto:bess@ietf.org>
List-Help: <mailto:bess-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/bess>, <mailto:bess-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Nov 2021 09:07:13 -0000

Hi Derek,

Thank you very much for reviewing.

The Security section (along with the other sections) has been improved quite a bit in the latest revision compared to version 09.

All in all, a forged BM packet sent into an EVPN PE will reach all the remote EVPN PEs of the same Broadcast Domain. The Assisted-Replication solution makes that replication no worse than that, i.e. forged BM packets injected into an EVPN PE acting as an AR-LEAF will be forwarded to all the remote EVPN PE/NVEs of the same Broadcast Domain.

Thanks.
Jorge

From: Derek Atkins via Datatracker <noreply@ietf.org>
Date: Thursday, October 7, 2021 at 2:53 PM
To: secdir@ietf.org <secdir@ietf.org>
Cc: bess@ietf.org <bess@ietf.org>, draft-ietf-bess-evpn-optimized-ir.all@ietf.org <draft-ietf-bess-evpn-optimized-ir.all@ietf.org>, last-call@ietf.org <last-call@ietf.org>
Subject: Secdir last call review of draft-ietf-bess-evpn-optimized-ir-09
Reviewer: Derek Atkins
Review result: Ready

Hi,

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written with the intent of improving
security requirements and considerations in IETF drafts.  Comments
not addressed in last call may be included in AD reviews during the
IESG review.  Document editors and WG chairs should treat these
comments just like any other last call comments.

Summary:

* Ready to Publish

Details:

* It is unclear to me how one would protect from a (D)DoS attack with
  a forged BM packet sent into the replicator and prevent
  amplification attacks.

-derek