[Gen-art] Gen-ART Telechat review of draft-ietf-ospf-security-extension-manual-keying-09.txt

Suresh Krishnan <suresh.krishnan@ericsson.com> Tue, 28 October 2014 22:22 UTC

Return-Path: <suresh.krishnan@ericsson.com>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4DFB51A005F for <gen-art@ietfa.amsl.com>; Tue, 28 Oct 2014 15:22:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level:
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fEo8NRKEPccK for <gen-art@ietfa.amsl.com>; Tue, 28 Oct 2014 15:22:19 -0700 (PDT)
Received: from usevmg20.ericsson.net (usevmg20.ericsson.net [198.24.6.45]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 363C31A0055 for <gen-art@ietf.org>; Tue, 28 Oct 2014 15:22:19 -0700 (PDT)
X-AuditID: c618062d-f79206d0000014d2-60-544fbf211cf9
Received: from EUSAAHC008.ericsson.se (Unknown_Domain [147.117.188.96]) by usevmg20.ericsson.net (Symantec Mail Security) with SMTP id CF.F4.05330.12FBF445; Tue, 28 Oct 2014 17:06:57 +0100 (CET)
Received: from [142.133.113.41] (147.117.188.8) by smtps-am.internal.ericsson.com (147.117.188.96) with Microsoft SMTP Server (TLS) id 14.3.174.1; Tue, 28 Oct 2014 18:22:17 -0400
Message-ID: <54501717.3020703@ericsson.com>
Date: Tue, 28 Oct 2014 18:22:15 -0400
From: Suresh Krishnan <suresh.krishnan@ericsson.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.2.0
MIME-Version: 1.0
To: draft-ietf-ospf-security-extension-manual-keying.all@tools.ietf.org, General Area Review Team <gen-art@ietf.org>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Originating-IP: [147.117.188.8]
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrFJMWRmVeSWpSXmKPExsUyuXRPgq7ifv8QgxXtphavJ4hbXH31mcWB yWPJkp9MHl8uf2YLYIrisklJzcksSy3St0vgyvj1cDtLwX2hiqvnxBsY7/N1MXJySAiYSNz+ vZgRwhaTuHBvPRuILSRwhFGi/41lFyMXkL2NUeLyp+dMIAleAW2J6Qs2soLYLAKqEsv+3gCL swEN2rDzM5DNwSEqECYxdSkPRLmgxMmZT1hAbBGBConNT96wg5QIC0RLLNuTDGIyC9hLPNha BlLBLCAvsf3tHGaICzQltq75zgpxmaLEi+M/mSYw8s9CMnQWQvcsJN0LGJlXMXKUFqeW5aYb GWxiBAbWMQk23R2Me15aHmIU4GBU4uE1mOYXIsSaWFZcmXuIUZqDRUmcd1btvGAhgfTEktTs 1NSC1KL4otKc1OJDjEwcnFINjHnWrFM37LTq4JKzUgxim9X+xWTm2o08h2Y3py3an9X4YPO9 l7+urZP9prxE7S7TtDuaMuFuGQIbbKW5avK51587f++v4Z72ivQVygET/QyZ7+3SKzbQOCeS 7W8a8mDDH11/r4f/RReLLFylv7T4eK/YHub6rSF8E4V9r2huWce3/eETSa+440osxRmJhlrM RcWJAIUoO3INAgAA
Archived-At: http://mailarchive.ietf.org/arch/msg/gen-art/609rRu7iBINtgDlTpGfKhGtlo_c
Subject: [Gen-art] Gen-ART Telechat review of draft-ietf-ospf-security-extension-manual-keying-09.txt
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Oct 2014 22:22:22 -0000

I have been selected as the General Area Review Team (Gen-ART)
reviewer for this draft (for background on Gen-ART, please see
http://www.alvestrand.no/ietf/gen/art/gen-art-FAQ.html)

Please wait for direction from your document shepherd
or AD before posting a new version of the draft.

Document: draft-ietf-ospf-security-extension-manual-keying-09.txt
Reviewer: Suresh Krishnan
Review Date: 2013/10/28
IESG Telechat date: 2013/10/30


Summary: The draft is almost ready for publication as Proposed Standard 
but has some issues that need to be addressed.

* Section 2

-> There is no reference to snmpEngineBoots in the RFC4222 reference. 
Are you pointing to the wrong document here? I would suggest replacing 
the RFC4222 reference with a reference to RFC2574 Section 2.2 that talks 
about replay protection.

-> There is another change to the 64-bit authentication field that is 
not described in the text. The 0 field in the beginning is extended from 
16 bits to 24 bits. Can you please add this.

* Section 5

-> It is unclear from this text what the exact change to the 
authentication trailer is. The only logical explanation I could come up 
with is that instead of initializing the field with Apad x times, we 
initialize with the IP source address x times. If my understanding is 
correct please reword the text. Suggested change below.

OLD:
    OSPF routers sending OSPF packets must initialize Apad to the value
    of the IP source address that would be used when sending an OSPFv2
    packet, repeated L/4 times, where L is the length of the hash,
    measured in octets.  The basic idea is to incorporate the IP source
    address from the IP header in the cryptographic authentication
    computation so that any change of IP source address in a replayed
    packet can be detected.

NEW:
    Instead of using the hexadecimal constant 0x878FE1F3, OSPF routers
    following this specification MUST initialize Apad to the value
    of the IP source address that would be used when sending an OSPFv2
    packet, repeated L/4 times, where L is the length of the hash,
    measured in octets.  The basic idea is to incorporate the IP source
    address from the IP header in the cryptographic authentication
    computation so that any change of IP source address in a replayed
    packet can be detected.

Thanks
Suresh