Re: [Isis-wg] Review of draft-ietf-isis-extended-sequence-no-tlv-04

Uma Chunduri <uma.chunduri@ericsson.com> Thu, 26 March 2015 18:43 UTC

Return-Path: <uma.chunduri@ericsson.com>
X-Original-To: expand-draft-ietf-isis-extended-sequence-no-tlv.all@virtual.ietf.org
Delivered-To: isis-wg@ietfa.amsl.com
Received: by ietfa.amsl.com (Postfix, from userid 65534) id DB39A1A92E0; Thu, 26 Mar 2015 11:43:22 -0700 (PDT)
X-Original-To: xfilter-draft-ietf-isis-extended-sequence-no-tlv.all@ietfa.amsl.com
Delivered-To: xfilter-draft-ietf-isis-extended-sequence-no-tlv.all@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BBB951A9241 for <xfilter-draft-ietf-isis-extended-sequence-no-tlv.all@ietfa.amsl.com>; Thu, 26 Mar 2015 11:43:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.234
X-Spam-Level:
X-Spam-Status: No, score=-1.234 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, SPF_SOFTFAIL=0.665] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NUjaOjXMDpkL for <xfilter-draft-ietf-isis-extended-sequence-no-tlv.all@ietfa.amsl.com>; Thu, 26 Mar 2015 11:43:21 -0700 (PDT)
Received: from zinfandel.tools.ietf.org (zinfandel.tools.ietf.org [IPv6:2001:1890:123a::1:2a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E88F91ABD36 for <draft-ietf-isis-extended-sequence-no-tlv.all@ietf.org>; Thu, 26 Mar 2015 11:43:20 -0700 (PDT)
Received: from usevmg21.ericsson.net ([198.24.6.65]:49694) by zinfandel.tools.ietf.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.82_1-5b7a7c0-XX) (envelope-from <uma.chunduri@ericsson.com>) id 1YbCkR-00035c-SH for draft-ietf-isis-extended-sequence-no-tlv.all@tools.ietf.org; Thu, 26 Mar 2015 11:43:20 -0700
X-AuditID: c6180641-f790b6d000004359-ec-5513f13ef91d
Received: from EUSAAHC004.ericsson.se (Unknown_Domain [147.117.188.84]) by usevmg21.ericsson.net (Symantec Mail Security) with SMTP id 45.87.17241.E31F3155; Thu, 26 Mar 2015 12:45:02 +0100 (CET)
Received: from EUSAAMB105.ericsson.se ([147.117.188.122]) by EUSAAHC004.ericsson.se ([147.117.188.84]) with mapi id 14.03.0210.002; Thu, 26 Mar 2015 14:43:10 -0400
From: Uma Chunduri <uma.chunduri@ericsson.com>
To: Alia Atlas <akatlas@gmail.com>, Nevil Brownlee <n.brownlee@auckland.ac.nz>
Thread-Topic: Review of draft-ietf-isis-extended-sequence-no-tlv-04
Thread-Index: AQHQZ+SAC42uZyGno0i39UZi4HczX50vVPyA///De4A=
Date: Thu, 26 Mar 2015 18:43:09 +0000
Message-ID: <1B502206DFA0C544B7A60469152008633F618FCC@eusaamb105.ericsson.se>
References: <551437E7.9030406@auckland.ac.nz> <CAG4d1rcB0qp0yiLNCTvQmhqvgWFSvSUDfVGCDe6F0MQGzwQ==w@mail.gmail.com>
In-Reply-To: <CAG4d1rcB0qp0yiLNCTvQmhqvgWFSvSUDfVGCDe6F0MQGzwQ==w@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [147.117.188.9]
Content-Type: multipart/alternative; boundary="_000_1B502206DFA0C544B7A60469152008633F618FCCeusaamb105erics_"
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFuplkeLIzCtJLcpLzFFi42KZXLonRNfuo3CowcPZyhafHl5itth38x27 xetbdxktepuWMDuwePz+/ZDRY+esu+weS5b8ZPL4cvkzWwBLFJdNSmpOZllqkb5dAlfGxmdb WQvW5VWcPnSerYFxQ3YXIyeHhICJxNTFf5khbDGJC/fWs3UxcnEICRxhlGg4vBzKWc4o0T1p IRtIFZuAnsTHqT/ZQWwRAT+JpqnXGUGKmAVWMUrcmvIcrEhYwEli+6xmJogiZ4kjSz5DNVhJ LDv+C6yGRUBV4sq8SawgNq+Ar8Sxh3fBzhASKJFYvXEyWD2nQKDEiZnrweoZgc77fmoN2Exm AXGJW0/mM0GcLSCxZM95qBdEJV4+/scKYStK7Oufzg5Rny9x4vpnZohdghInZz5hmcAoOgvJ qFlIymYhKZvFyAEU15RYv0sfokRRYkr3Q3YIW0Oidc5cdmTxBYzsqxg5SotTy3LTjQw3MQLj 75gEm+MOxgWfLA8xCnAwKvHwfrAVDhViTSwrrsw9xCjNwaIkzlt25WCIkEB6YklqdmpqQWpR fFFpTmrxIUYmDk6pBkbPGe/n3tTYkc/pfHLJtdXPviWscbf923Fya+POgsc/Nvj8fBX0IyRV RI6L8cbNyS8q/DZFLz3x9mHu15Nmd41/cSx7fOBiK+O+Q5Li7x0v7AoPqt1zT0ky5JJb3XTz ogmZt07/LnzjlHzEZm36uUop3rwbb9VvRijfNRVxeLP5xq2uAK9utx9RSizFGYmGWsxFxYkA 6rbMIKACAAA=
X-SA-Exim-Connect-IP: 198.24.6.65
X-SA-Exim-Rcpt-To: draft-ietf-isis-extended-sequence-no-tlv.all@tools.ietf.org
X-SA-Exim-Mail-From: uma.chunduri@ericsson.com
X-SA-Exim-Version: 4.2.1 (built Mon, 26 Dec 2011 16:24:06 +0000)
X-SA-Exim-Scanned: Yes (on zinfandel.tools.ietf.org)
Resent-To: draft-ietf-isis-extended-sequence-no-tlv.all@ietf.org
Resent-Message-Id: <20150326184320.E88F91ABD36@ietfa.amsl.com>
Resent-Date: Thu, 26 Mar 2015 11:43:20 -0700
Resent-From: uma.chunduri@ericsson.com
Archived-At: <http://mailarchive.ietf.org/arch/msg/draft-ietf-isis-extended-sequence-no-tlv.all@tools/XuFVKELNufxt-JEyCCAApmINV30>
Archived-At: <http://mailarchive.ietf.org/arch/msg/isis-wg/cOVH3hMOyKXP9jQStEtfWfGmA9s>
X-Mailman-Approved-At: Sun, 29 Mar 2015 04:04:47 -0700
Cc: "ops-dir@ietf.org" <ops-dir@ietf.org>, "draft-ietf-isis-extended-sequence-no-tlv.all@tools.ietf.org" <draft-ietf-isis-extended-sequence-no-tlv.all@tools.ietf.org>
Subject: Re: [Isis-wg] Review of draft-ietf-isis-extended-sequence-no-tlv-04
X-BeenThere: isis-wg@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF IS-IS working group <isis-wg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/isis-wg>, <mailto:isis-wg-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/isis-wg/>
List-Post: <mailto:isis-wg@ietf.org>
List-Help: <mailto:isis-wg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/isis-wg>, <mailto:isis-wg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 26 Mar 2015 18:43:23 -0000

Hi Nevil,

Thank you very much for the review and suggestions.

We shall  take care of both the comments (in-line [Uma] below) in the next revision
along with routing directorate’s review comments.
--
Uma C.

From: Alia Atlas [mailto:akatlas@gmail.com]
Sent: Thursday, March 26, 2015 1:16 PM
To: Nevil Brownlee
Cc: ops-dir@ietf.org; draft-ietf-isis-extended-sequence-no-tlv.all@tools.ietf.org
Subject: Re: Review of draft-ietf-isis-extended-sequence-no-tlv-04

Nevil,

Thanks very much for the review.

Alia

On Thu, Mar 26, 2015 at 12:46 PM, Nevil Brownlee <n.brownlee@auckland.ac.nz<mailto:n.brownlee@auckland.ac.nz>> wrote:

Hi all:

I have reviewed this document as part of the Operational directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written primarily for the benefit of the
operational area directors.  Document editors and WG chairs should
treat these comments just like any other last call comments.

Overall, it seems fine to me.

Abstract:
  "This document defines Extended Sequence number TLV to protect
   Intermediate System to Intermediate System (IS-IS) PDUs from replay
   attacks."

Draft addresses Security concerns raised by the use of IS-IS in
Data Centre environments, and by the use of SDN in Data Centres.

"This document defines Extended Sequence number (ESN) TLV to protect
Intermediate System to Intermediate System (IS-IS) PDUs from replay
attacks."

[Uma]: Ack.


I presume that the ESSN will be given a random (but non-zero) when the
router boots up, then increments from there?
[Uma]: Yes, that’s correct.

This is covered in
detail in Appendix A, but perhaps a forward reference to that in
section 3 would be helpful.

[Uma]:  Sure, shall do that.


Section 5 on Backward Compatibility and Deployment seems clear
to me, and should help Operators to use this new feature.

Cheers, Nevil
Co-chair, EMAN WG

--
---------------------------------------------------------------------
 Nevil Brownlee                    Computer Science Department | ITS
 Phone: +64 9 373 7599 x88941<tel:%2B64%209%20373%207599%20x88941>             The University of Auckland
 FAX: +64 9 373 7453<tel:%2B64%209%20373%207453>   Private Bag 92019, Auckland 1142, New Zealand