[mpls] Kathleen Moriarty's Discuss on draft-ietf-mpls-lsp-ping-reply-mode-simple-04: (with DISCUSS)
Kathleen Moriarty has entered the following ballot position for draft-ietf-mpls-lsp-ping-reply-mode-simple-04: Discuss When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html for more information about IESG DISCUSS and COMMENT positions. The document, along with other ballot positions, can be found here: https://datatracker.ietf.org/doc/draft-ietf-mpls-lsp-ping-reply-mode-simple/ ---------------------------------------------------------------------- DISCUSS: ---------------------------------------------------------------------- This should be easy to resolve. SInce this draft adds a new capability to include the return path, this provides another attack vector to observe path information that could be part of reconnaissance gathering to later attack the network or path. While the referenced RFC4379 mentions the following in the security considerations section: The third is an unauthorized source using an LSP ping to obtain information about the network. The equivalent should be added for this new capability in this draft, since now it's possible to gather the path information from the new feature.
