[Detnet] Secdir last call review of draft-ietf-detnet-pof-06

Scott Kelly via Datatracker <noreply@ietf.org> Mon, 11 December 2023 23:12 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: detnet@ietf.org
Delivered-To: detnet@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 9B2EFC15155A; Mon, 11 Dec 2023 15:12:20 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Scott Kelly via Datatracker <noreply@ietf.org>
To: secdir@ietf.org
Cc: detnet@ietf.org, draft-ietf-detnet-pof.all@ietf.org, last-call@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 11.16.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <170233634062.42112.4492248784717977119@ietfa.amsl.com>
Reply-To: Scott Kelly <scott@hyperthought.com>
Date: Mon, 11 Dec 2023 15:12:20 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/detnet/HGMhUZwf5E9cboJdjuFTfskJtmQ>
Subject: [Detnet] Secdir last call review of draft-ietf-detnet-pof-06
X-BeenThere: detnet@ietf.org
X-Mailman-Version: 2.1.39
List-Id: Discussions on Deterministic Networking BoF and Proposed WG <detnet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/detnet>, <mailto:detnet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/detnet/>
List-Post: <mailto:detnet@ietf.org>
List-Help: <mailto:detnet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/detnet>, <mailto:detnet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Dec 2023 23:12:20 -0000

Reviewer: Scott Kelly
Review result: Ready

I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG. These comments
were written primarily for the benefit of the security area directors. Document
editors and WG chairs should treat these comments just like any other last call
comments.

I'm sorry this review is a few weeks late -- I hope it is still useful.

The summary of the review is ready.

RFC8655 describes Deterministic Networking (DetNet) Architecture. The document
under review covers a specific aspect of DetNet: the packet ordering function.
>From the document abstract,

   The Packet Ordering Function (POF)
   algorithm described herein enables to restore the correct packet
   order when replication and elimination functions are used in DetNet
   networks.

Here is the security considerations section in its entirety:

   PREOF related security considerations (including POF) are described
   in section 3.3 of [RFC9055].  There are no additional POF related
   security considerations originating from this document.

I believe that RFC9055 (Deterministic Networking (DetNet) Security
Considerations) does indeed cover all relevant security considerations. I see
no security issues with this draft.