Re: [Idr] Rtgdir telechat review of draft-ietf-idr-bgp-gr-notification-15

"John G. Scudder" <jgs@juniper.net> Tue, 17 April 2018 19:48 UTC

Return-Path: <jgs@juniper.net>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7087D126CF6; Tue, 17 Apr 2018 12:48:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 16lNckICMGUR; Tue, 17 Apr 2018 12:48:01 -0700 (PDT)
Received: from mx0a-00273201.pphosted.com (mx0a-00273201.pphosted.com [208.84.65.16]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6EA3C126CC4; Tue, 17 Apr 2018 12:48:01 -0700 (PDT)
Received: from pps.filterd (m0108158.ppops.net [127.0.0.1]) by mx0a-00273201.pphosted.com (8.16.0.22/8.16.0.22) with SMTP id w3HJ0kqS022254; Tue, 17 Apr 2018 12:06:55 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=content-type : mime-version : subject : from : in-reply-to : date : cc : content-transfer-encoding : message-id : references : to; s=PPS1017; bh=1wA8KhIcRSTBKYWhB6DqLnkfWRrFICkeOiVrpWJGh84=; b=y9ggz9vCXoqR3BR1RKYxDTJeXz08ZFkIh7l+3LxgEE7Rc4A+bqYXMcbn0C6UPAG9XOTY y9/H4MHqMb68+UwMqi/3Ecs9GkhS/2LBirvJdGieOM/jaG5h2vLNM7YeOVVzbutkWOzk jiMXMyY03IGao1Y9fK4TcONs5gVK3hj7Ub4y8GmWpD0Rc435gFKRDKkFi4QA9oJ+L6Qp jG2qBj2zYaheVCWIyGMofHgT0xxtY1zHmP5S9SswDp3xL8UeN9FbVYFx8jY722qI9DB2 Q92DJMUc8lgbpn2nBGAWb6WR7O0/aFO2i1XA+UtVe4hXnXU/boq8qZBEzpV6zIzyFAdT 4g==
Received: from nam03-by2-obe.outbound.protection.outlook.com (mail-by2nam03lp0054.outbound.protection.outlook.com [216.32.180.54]) by mx0a-00273201.pphosted.com with ESMTP id 2hdhds0q9q-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Tue, 17 Apr 2018 12:06:54 -0700
Received: from [192.168.42.7] (75.151.14.9) by SN1PR0501MB2077.namprd05.prod.outlook.com (2a01:111:e400:5962::26) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.696.8; Tue, 17 Apr 2018 19:06:51 +0000
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: "John G. Scudder" <jgs@juniper.net>
In-Reply-To: <152361434369.26334.5582212241569156147@ietfa.amsl.com>
Date: Tue, 17 Apr 2018 15:06:45 -0400
Cc: rtg-dir@ietf.org, "idr@ietf. org" <idr@ietf.org>, ietf@ietf.org, draft-ietf-idr-bgp-gr-notification.all@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <6EF20184-1A21-4D95-9114-F750D4394B55@juniper.net>
References: <152361434369.26334.5582212241569156147@ietfa.amsl.com>
To: Bruno Decraene <bruno.decraene@orange.com>
X-Mailer: Apple Mail (2.3273)
X-Originating-IP: [75.151.14.9]
X-ClientProxiedBy: MWHPR11CA0046.namprd11.prod.outlook.com (2603:10b6:300:115::32) To SN1PR0501MB2077.namprd05.prod.outlook.com (2a01:111:e400:5962::26)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-HT: Tenant
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(5600026)(4534165)(4627221)(201703031133081)(201702281549075)(48565401081)(2017052603328)(7153060)(7193020); SRVR:SN1PR0501MB2077;
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB2077; 3:XLE/7mf99qzfXJdn6tv0okTRzvDXv+sUi1KXAuJdnRBRKa3sTCE56b7+xEfCWyp9DltL6Lq2HAZlgIorJWY6w0CqYs7AxHlc8C0EzKljeTtZIrCZ2B+wvAKjQXFA8ljh0LAlApT2hj5GsniJK89GvU3gLQiIFfvU6Tki59zspyfmjIRyeHEvCTC1N9H10jZpveHXOsaAnc8BVqfz3tSeh+WGwCDZjxlSX04ZvojPnHHBXl65IS5x1Bzcs36Vor/m; 25:xi9KCmHY3GrLXILsLWs+xQmeJTgnjKNQ35CxAd9BWiJ7zA8yuIiaX11EnV2GC7rjz5hxYKgMDzBr7UHgkrdcddnFh8zxsXylJMK2agDs2s3o03ODne0FJoU4KZavDOdgxzU3AUncD+9lcV4SJMTfpaUoqU4BsHC3N/ck99QD0kYgrVluH5H6Of3acJvEs1UJVD0vSHO1qMJsMWRSrp8rU2sWj8kRim5d08dO9WEueYWFeZPMkorJi47ePSouA6xItBnBBXcP8e7FjKFhojLw3/kkeUr/g/EXcEM5e23tA+YJLvRPaj5f9a9kx0ijNpZXn8xgUESA1boMCNWvpQjjZA==; 31:/TVsaac75kwV8Css1041Ha0MdXjyf0sa0NlAsxvSGs3tbGKU5V1zpIIblBBcQiXTP6IN237MBAWjFL+Y5zBeWTtW/gp7Y3t2SKFf3LygYaezIR0jjUvgQrhk/L4Dl72zjUgu7gHUOfGG6FG1yLTcXlrtMNTBP8NTX3UanbpETWN2QojgUQgeh9dWpHG6LGYb8Ro90sNipSalzUWzf80cBdhJEYMkK7FZSMM58kCX4CQ=
X-MS-TrafficTypeDiagnostic: SN1PR0501MB2077:
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB2077; 20:TITm/cpeV/XPx0htX89NoIidINjQlHrh+GPX19w6lsCkKwPLgZpY+8Xjam0L9Y2Fs3sHeJL4yy0+vRM6one+pwUSrJjcguC+YYMpHFLoHngVXOIfyXfGmWAagBGUthMHbrgYSdLhgp17uSRRxaKFqSde5SMhMw/NKYvrTGfPp0ndsvDN1P/TPUO7Uu612eGY6Xr6tE5hgvMEtKODb5qX1z+58k247UY5Tv/BDGLCbLXes0V/oC4W++xb9KYqji4/CHMBMBnft4npFz3a1Or5gOzaNz63ZLGX1TXut6dM5+Grfo5yldZE4Up04B25h47r3tUtPnXzXF2dH+8xuwm172QEIbv3OQ4z+pi7rTlD90aRnP59tqdhVY6m69LbdnL+QEZSpxuPDi0+yfJK1Gc5AJ+OOHVVQqfWboCku0urg3z4K6rTvf97S/C+lEJn9hIF3VQx52zZXi67rv8oPhH2rvuwMuB8wFsNhZWmXP5EVdsmXM9r2SIy++k2vBRfgJ3t; 4:Zgz47BJoz2KviY4WdtNn43vIppBAgLh67Hwdfyn4qDMbml1y7PaatqL/1TqF/v798nXx5X3TLiFIYmPIAcehDqowYz2n6hkXhw+WZbOv0Ro9ax1v0e1Bg1Z46N1XLFnu5XPd4Fl5xEWCoBPQxoH87GXoeOak3NiZgr7U3G0+9LR//VnpdwRwvbgbGEPJG10mvavODV1uKtA3R8fp9bIEVPoPkP9bf1Wuw34LR991FzDgcQXtMP2IwzUNmpOA51+ePM4ZsLuUANKT+w7enzIkoLTCMo1Eqpezt8cgxVhV3oMKdd78YFm1FRLjinbuOeYKOuAUdsjlA5yDjbLAxhsL8SFLx1lXDulS4M1Iw6ORadpQ1sZABj6zey0adMUyg17e
X-Microsoft-Antispam-PRVS: <SN1PR0501MB207784D1495A0691039D36BEAAB70@SN1PR0501MB2077.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(10436049006162)(192374486261705)(18271650672692);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(5005006)(8121501046)(3231232)(944501327)(52105095)(10201501046)(93006095)(93001095)(3002001)(6055026)(6041310)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123562045)(20161123560045)(20161123564045)(20161123558120)(6072148)(201708071742011); SRVR:SN1PR0501MB2077; BCL:0; PCL:0; RULEID:; SRVR:SN1PR0501MB2077;
X-Forefront-PRVS: 0645BEB7AA
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(6049001)(396003)(39860400002)(366004)(346002)(376002)(39380400002)(69234005)(51914003)(189003)(199004)(377424004)(77096007)(50466002)(81156014)(8746002)(97736004)(50226002)(8936002)(57306001)(486006)(16576012)(316002)(117156002)(2616005)(476003)(446003)(52116002)(15650500001)(106356001)(2486003)(52146003)(76176011)(23676004)(956004)(11346002)(105586002)(6116002)(478600001)(3846002)(81166006)(8676002)(2906002)(33656002)(82746002)(66066001)(7736002)(47776003)(36756003)(68736007)(6916009)(6486002)(4326008)(53936002)(305945005)(25786009)(186003)(6666003)(16526019)(53546011)(386003)(5660300001)(59450400001)(86362001)(229853002)(575784001)(6246003)(83716003)(26005)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:SN1PR0501MB2077; H:[192.168.42.7]; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
Received-SPF: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1;SN1PR0501MB2077;23:YDmn4efysJqWm6VOnOW8yyVqv62Nsz6Vor5it3coZD3eC4Ch2erx5DSXV+hslqnydQ8+NNIXrSjQky1xCqQj8mlhlwsCYe5fvwbdhLnXO6W3TjO9ORcANcNGwwhT9/LBjJRMJS4d5iS/QLpJWyfHRUVO08ZvLm9HoRPXY2OPKABCLwAdqQ7Hsq227a5zZmEKXRhACN03Ha+31MD69fa+djKzE2UDvIbO5NZ4742jrXDCG7GZUhSsLNwZfcGSOM2HxaZMkJ+qEi0BPHOFqFc9fUDoT2Kew2lyQ80YlLHSP1FdpIZ1TPibLnLJqWDNdHtNCxt+vZ0OGWGbBB8noqJL9W8AyqXLyWTxguW0TWIlMzmKn/BtkqRqAsI9FQ0+rfskRyL6qK+AzIdWGVjOM3ZgLTSN3NdExXDp43iz+okVPmm8rcXb4eWJlkfqpK2Xa1v6VZOBaoGep6KvN7xUg2ePogGNkv0CrGGQuv6QLLb/CTfyEcTQBh8h/7GPEFTszTohXZ5x8gLRTmlgG0R6jbKnwOvu8cMhTENWIxRiR5bMFL+KJjo3g3B3SYBYKJ+atD3cSmkKOmyRggvSsBTFGAT/8WrMlWvxivD6tjwrdj67UQMEk6MhSfA98ZIkBfajcokA0xhlur7dXO7CBoIjmQTWoaODwEVkAEaVYh402FLmvnQG4d9plIZt2hSVsCbObaCSpHbPfeJPLUH0NGZ5u76BzZ7NrvpVEfoq5BM7tr6mipNwABXD3bc1XRIr6Rd7TSuRnjkht4dKNQkAWRG62KIljmYI+tzI9eTVExBpvym1sVNlawmsu3gA2PB68QsAO1cRVcVyZHX0lml0bCNmuqFxRfke7N3dPN+CJ7f8IIoRtysoM8y3QT7Sd8issXsBE60a89wvOLlgP7SSjHPNJ3/9FRA1ChBpT8BLQHNYxwTKW/ZtNIFC5Xdu51rQxJdsjeZQz8Kp5e/aiXCTfuoLpY1VAKmVIO1aNY9/CQ5HSXnoC/Wix02YMVgiXjwOV+xrdtNf0UhHQwBaVRJvgixuqYuGVOb6vIVk1AnXdIfPIMWQhyNNCTnSZIl1W3tNz3PH8WMW4uRSHF+cceS4ozyNJGmr4bpZVJHlWOTK0p+OHLGRH6O7bZP7HAyHG4FiZ2+wW4knx2i9i4epmut4nBp5CvdDetHatXeZZhzM9FMhBsFRGccdcNG1hw+MSx3J014L/DO7m4sNrLh0qH1U+AU7DEZEjne1MkbPATW42vdOi/zOkkyLxlDDN8Yb83p+hTAWULP6kLx0Rjb8weKU0jaN5DYPP45zVw5RopL0dqm5j5AZg2r2M0JbdeR3GfAMhZ+tcOWe86s4+cQVeNq9Qcq8R+H4Sq6tr3GNkRWp5qxzOgVCkX9YtCBl0pPrIsOTKK2u9Xn6fefGH4UnG3Vt9cjua9FxLyKAC9nzbc38NluBVn/bbvemQi1Qzi/luPuElp6LX++g66pe4hRsliyi7LseiX+DUrSlhFX+NQbedm+/13ZllWuwG5WmJpSvciFDWHwDAcVUvbFbfDfwu5znEqnQZWd1sw==
X-Microsoft-Antispam-Message-Info: dtAcWg9QIY+J2keNfAfg9Hffp3wgGmrOiaWuczsPriwPnVWhfextsSJnfL4fg6/dkHX5AZrUXLxmIdDgdvssdeV2aomRQR8DtKOpXOmZ0jZNAm6Nk9fWkVJuz3gqL8JaCjwRFXpM+99ODJP9wvVh7P/hoewn5VFFMR97uqQBvjZT0NiEjwHWN1dEme8mYPaL
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB2077; 6:foCIVeC9w47ZmUZdwjAHJHdQVrgS5yPmQu4cWan/+e16lCW0WBObuVnsVvsgri9cL5vQQR+lRSma5ZecBLE6PSsyXzWgzeAU+Luat2kDdPEuHjMkeIhVG1PcEJ97x0RWsVHPCKYXYUvr3ZQk+E5DWC1B8DyQyPAaMfagNHdFdI+j70xrtzvVbVH3aC372RYMCSXZRNNHnFIG3OVoACnSrVDn4XYpXBDUKZOw/2YtX7b7mdnHvkxtyd1/E1yN7Nvu62VHjldM5ZyHQ4M8t3CtTWgM3pYcvK1uSyg3NeeMsx20d5x1r4pwWU6JNDTkqHGqIq3XlNp7ljWCk7ICBw/1a4muQCaxsvnN9MvP9NgkiyEB2S1sO20BHcJi939nyStLRROUYpvJnG5uaq1hoyHgFHMjMVQXqn+ZpQDwZWPBDoDIGrVuNct3sS3eft2HfETa/NBD0yheXIJGVj97wfFfYQ==; 5:PdHeOA8IuBa4haVloYSE9ZJCGnURXMD84BHTrx2f9FYWKG7Ph/nHcDTUbM/Sd4y4X37ONLqASXK92Y5ePcf/T+rmNSeaHGqQycrIc/apgs2uydvI4xbZAFeWVCNDELArhjtEWeurtySwe9gTAjZfNUvB81dRIeOsn5co+3qk0Sg=; 24:LK2XYjdcxWk8v1W5hl5lIS4CKLZ9ji282kqk6KtsqIGZoFAmQV5VcT3qcjGerkVmUoyvR+d6li5LX3IcsyRKe6Y2Rs+9v+kQ7UxhOG24t0g=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB2077; 7:vPC9WMmiWjtRuXnwKZIF60/s82bAoCZgAAK1Y5I5/yJ3bYWL1riSvg45XOdHM+ux2zIG35Xf4MZiySROwlYk+8MSOsH+Pfcg7qujj+Fy77q8hCVO6/i9FgzsyvRHNfsX8FvsxCg0ccgqGtseC9atLCMiX/Gg6rqaL1/eY7c5LyjEePe0oCZXAW9rsiiXYFsAObsu4WItZXzueZLXXdByEIvikvUtpGXTH59GkhpmKepKtfmgdWfZWj/Eftc2ErJ7
X-MS-Office365-Filtering-Correlation-Id: e5293cfd-fb8c-453d-ad9f-08d5a496615d
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Apr 2018 19:06:51.8840 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: e5293cfd-fb8c-453d-ad9f-08d5a496615d
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR0501MB2077
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2018-04-17_09:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1711220000 definitions=main-1804170164
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/viXQXsngLosdbypk117wE95L_g0>
Subject: Re: [Idr] Rtgdir telechat review of draft-ietf-idr-bgp-gr-notification-15
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Apr 2018 19:48:04 -0000

Hi Bruno,

Thanks for the further review. Some discussion in line below.

> On Apr 13, 2018, at 6:12 AM, Bruno Decraene <bruno.decraene@orange.com> wrote:
> 
> Reviewer: Bruno Decraene
> Review result: Ready
> 
> Hello,
> 
> I have been selected as the Routing Directorate reviewer for this draft. The
> Routing Directorate seeks to review all routing or routing-related drafts as
> they pass through IETF last call and IESG review, and sometimes on special
> request. The purpose of the review is to provide assistance to the Routing ADs.
> For more information about the Routing Directorate, please see
> ​https://urldefense.proofpoint.com/v2/url?u=http-3A__trac.tools.ietf.org_area_rtg_trac_wiki_RtgDir&d=DwIDaQ&c=HAkYuh63rsuhr6Scbfh0UjBXeMK-ndb3voDTXcWzoCI&r=hLt5iDJpw7ukqICc0hoT7A&m=gDChh7wheTA_cW1uNH2O1ZzaT4Ni4sju5OjDqAYKXII&s=CoXU6i3CuhDJ37j7puwilN_1e9W2p0HoSzX-veANZ2w&e=
> 
> Although these comments are primarily for the use of the Routing ADs, it would
> be helpful if you could consider them along with any other IETF Last Call
> comments that you receive, and strive to resolve them through discussion or by
> updating the draft.
> 
> Document: draft-ietf-idr-bgp-gr-notification-15
> Reviewer: Bruno Decraene
> Review Date: 2018-04-13
> IETF LC End Date: 2018-04-24
> Intended Status: Standards Track
> 
> =====
> Summary: No issues found. This document is ready for publication.
> 
> =====
> Comments:
> 
> The document is very clear. I have particularly appreciated the high level
> summary of the document in the introduction section. Thanks to the authors. The
> security consideration section adequately consider the security impacts of this
> specification. I had already reviewed the document twice (WGLC, AD review)
> hence I really needed to push in order to find some comments. In this
> nitpicking context, any comment is really up to the authors.
> 
> =====
> Major Issues: No major issues found.
> 
> =====
> Minor Issues:
> 
> I would not call these "minor issue", but it's beyond editorial so do not
> qualify as "Nits". Please find below 2 comments, on the nitpicking far side.
> 
> "If the "N" bit has not been exchanged with the peer, then to
>        deal with possible consecutive restarts, a route (from the peer)
>        previously marked as stale MUST be deleted."
> [...]
> "To put an upper bound on the amount of time a router retains the
>        stale routes, an implementation MUST support a (configurable)
>        timer, called the "stale timer", that imposes this upper bound."
> 
> In order to fully respect the semantic, in case of consecutive restarts (with
> partial route readvertisement), it seems that the stale timer would need to be
> on a per route basis. I don't think that this is the intention of the authors
> (nor that this is desirable). Altough this is a local consideration, hence not
> affecting the peer, the "MUST" make this statement strong. Eventually, a text
> could be added saying that the timer only needs to be on a per session basis.
> e.g., :s/this upper bound/this upper bound on a per session basis.

I'll give this some thought, thanks.

> ---- "This
> specification doesn't change the basic security model inherent
>   in [RFC4724], with the exception that the protection against repeated
>   resets is relaxed. To mitigate the consequent risk that an attacker
>   could use repeated session resets to prevent stale routes from ever
>   being deleted, we make the stale routes timer mandatory (in practice
>   it is already ubiquitous)."
> 
> FYI, I'm not completely sure to see why this document change (i.e. negatively
> impacts) the security in case of repeated NOTIFICATION as I would assume that
> if an attacker could sends such NOTIFICATION, it could already advertise the
> routes that it wished were never deleted.

Well, an attacker might cause a session reset without the ability to insert data into the TCP stream I guess, e.g. with a RST attack. You are correct that there are other mitigations against such attacks, of course.

> Also this risk would be covered via
> an adequate protection against illegitimate messages (e.g. crypto checksum,
> GTSM for EBGP) However I do see an increased risk with regards to Hold Time
> expiration which remains an attack vector even with the use of a crypto
> checksum protection, by simply filtering some BGP packets. Especially in
> deployments when the BGP session crosses a long distance or multiple links and
> nodes (e.g. IBGP, layer 2 network within an IXP cf RFC 8327). May be I would
> propose to raise this point or slightly rephrase on the Hold Time expiration
> side, rater than the NOTIFICATION side.

If I understand you correctly, your point is that (a) an attacker can cause a holdtime expiration by filtering BGP traffic and (b) this technique provides some mitigation of that by additionally retaining the routes for the restart time? I'm a little hesitant to claim this as a real security benefit because for an attacker to be in position to filter BGP traffic, they presumably would also be in a position to filter user traffic. Furthermore, if they can do it for the duration of the holdtime they can probably also do it for the duration of the holdtime plus the restart time. 

But security sections are an exercise in speculative thinking. 

> 
> =====
> Nits:
> 
> §1.1
> RFC 2119 has been updated by RFC 8174.
> OLD:
>   The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
>   "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this
>   document are to be interpreted as described in RFC 2119 [RFC2119].
> 
> NEW:
>      The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL
>      NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED",
>      "MAY", and "OPTIONAL" in this document are to be interpreted as
>      described in BCP 14 [RFC2119] [RFC8174] when, and only when, they
>      appear in all capitals, as shown here.
> 
> 
> + New ref to RFC8174

Thanks!

> ----
> §2
> "("N") is defined as the BGP Graceful Notification bit"
> [...]
> "its Graceful NOTIFICATION bit set (value 1)"
> 
> Nitpicking, naming is not consistent.

OK.

> ---
> " This also implies support for the format for a BGP NOTIFICATION Cease message
> defined in [RFC4486]."
> 
> I'm not completely sure to see what this sentence is exactly saying. I feel
> that the sentence would benefit from beeing more specific. e.g. NEW:  This also
> implies support for the new "Hard Reset" subcode of the BGP NOTIFICATION Cease
> message, its new behavior and new encoding of the Data field.

I think the point of that sentence is that RFC 4271 doesn't talk about subcodes for Cease, and now we are defining a new subcode, so in principle we need support for both 4271 and 4486 (which does define subcodes). That said, the sentence doesn't really add much and perhaps it's perfectly obvious, so even deleting it might be fine. I'll think about it.

> ---- §8 "the
> reference this document and [RFC4724]"
> 
> OLD:
>       +--------------+------------------+------------+-----------+
>       | Bit Position |       Name       | Short Name | Reference |
>       +--------------+------------------+------------+-----------+
>       |      0       | Forwarding State |     F      | [RFC4724] |
>       |     1-7      |    unassigned    |            |           |
>       +--------------+------------------+------------+-----------+
> 
> NEW:
>       +--------------+------------------+------------+---------------+
>       | Bit Position |       Name       | Short Name |   Reference   |
>       +--------------+------------------+------------+---------------+
>       |      0       | Forwarding State |     F      |   [RFC4724]   |
>       |     1-7      |    unassigned    |            | This document |
>       +--------------+------------------+------------+---------------+

Right, thanks.

--John