[Pce] 答复: Secdir last call review of draft-ietf-pce-pcep-extension-native-ip-34

Aijun Wang <wangaijun@tsinghua.org.cn> Thu, 22 August 2024 08:08 UTC

Return-Path: <wangaijun@tsinghua.org.cn>
X-Original-To: pce@ietfa.amsl.com
Delivered-To: pce@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A1F9AC1840F6; Thu, 22 Aug 2024 01:08:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.909
X-Spam-Level:
X-Spam-Status: No, score=-6.909 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wA4MqxMpx73T; Thu, 22 Aug 2024 01:07:58 -0700 (PDT)
Received: from mail-m25473.xmail.ntesmail.com (mail-m25473.xmail.ntesmail.com [103.129.254.73]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1A882C14F71C; Thu, 22 Aug 2024 01:07:53 -0700 (PDT)
Received: from LAPTOP09T7970K (unknown [219.142.69.76]) by smtp.qiye.163.com (Hmail) with ESMTPA id D2FE27E0159; Thu, 22 Aug 2024 16:07:46 +0800 (CST)
From: Aijun Wang <wangaijun@tsinghua.org.cn>
To: 'Magnus Nyström' <magnusn@gmail.com>, secdir@ietf.org
References: <172430105731.2466060.3086653842488587585@dt-datatracker-6df4c9dcf5-t2x2k>
In-Reply-To: <172430105731.2466060.3086653842488587585@dt-datatracker-6df4c9dcf5-t2x2k>
Date: Thu, 22 Aug 2024 16:07:46 +0800
Message-ID: <002801daf46a$5f93bf80$1ebb3e80$@tsinghua.org.cn>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQMPhH0j1hs+i2nP7znJaneaAGq4r6/JwwFQ
Content-Language: zh-cn
X-HM-Spam-Status: e1kfGhgUHx5ZQUpXWQgPGg8OCBgUHx5ZQUlOS1dZFg8aDwILHllBWSg2Ly tZV1koWUFKTEtLSjdXWS1ZQUlXWQ8JGhUIEh9ZQVlDQ05OVhlKTkwdSB0ZSklOSlYeHw5VEwETFh oSFyQUDg9ZV1kYEgtZQVlJSkJVSk9JVU1CVUxNWVdZFhoPEhUdFFlBWU9LSFVKS0lIQkhCVUpLS1 VKQktLWQY+
X-HM-Tid: 0a917920a06e03a2kunmd2fe27e0159
X-HM-MType: 10
X-HM-Sender-Digest: e1kMHhlZQR0aFwgeV1kSHx4VD1lBWUc6Ogg6HSo6HTIyGi40OT0VDxMO PTEaC0pVSlVKTElPSEpPS01MTkpJVTMWGhIXVQwaFRwaEhEOFTsPCBIVHBMOGlUUCRxVGBVFWVdZ EgtZQVlJSkJVSk9JVU1CVUxNWVdZCAFZQU9OQk03Bg++
Message-ID-Hash: 5IC5HMQFESQVJKVHMEFESKBYCLIVQI46
X-Message-ID-Hash: 5IC5HMQFESQVJKVHMEFESKBYCLIVQI46
X-MailFrom: wangaijun@tsinghua.org.cn
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-pce.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-pce-pcep-extension-native-ip.all@ietf.org, last-call@ietf.org, pce@ietf.org
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Pce] 答复: Secdir last call review of draft-ietf-pce-pcep-extension-native-ip-34
List-Id: Path Computation Element <pce.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/pce/GhIIZYuytnAUvXiCpAeYiZwcNjA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pce>
List-Help: <mailto:pce-request@ietf.org?subject=help>
List-Owner: <mailto:pce-owner@ietf.org>
List-Post: <mailto:pce@ietf.org>
List-Subscribe: <mailto:pce-join@ietf.org>
List-Unsubscribe: <mailto:pce-leave@ietf.org>

Hi, Magnus:

Thanks for your comments and suggestions. I have updated the document and will submit it together with other expert's review.
Some detail responses are inline below.


Best Regards

Aijun Wang
China Telecom

-----邮件原件-----
发件人: forwardingalgorithm@ietf.org [mailto:forwardingalgorithm@ietf.org] 代表 Magnus Nystr?m via Datatracker
发送时间: 2024年8月22日 12:31
收件人: secdir@ietf.org
抄送: draft-ietf-pce-pcep-extension-native-ip.all@ietf.org; last-call@ietf.org; pce@ietf.org
主题: [Pce] Secdir last call review of draft-ietf-pce-pcep-extension-native-ip-34

Reviewer: Magnus Nyström
Review result: Has Nits

I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. 
Document editors and WG chairs should treat these comments just like any other comments.

- It is clear that Section 10 and Section 11 are intended to be normative since they contain capitalized keywords (e.g., "SHOULD"). However, it is not clear to me if Section 9 is intended to be normative or informative. There are several lower-case "should" in Section 9 which makes me suspect that the Section is informative, but would be good to clarify.

【WAJ】:Normative. I have switched "should" with "SHOULD" in this section and other parts within the document.

- Security Considerations: This section contains the following text: "To prevent a bogus PCE from sending harmful messages to the network nodes, the network devices should authenticate the validity of the PCE and ensure a secure communication channel between them.  Thus, the mechanisms described in [RFC8253] for the usage of TLS for PCEP and [RFC9050] for malicious PCE should be used." Firstly, did this intend to just say "authenticate the PCE"? I am not sure what "authenticate the validity" means, and it seems that authentication of the PCE should suffice (assuming that it, after having been authenticated, can be identified as a valid PCE)?
【WAJ】Yes. "Authenticate the PCE" is enough. Have omitted the "validity" in the updated document. Thanks for your clarification. 

Secondly, did the second sentence intend to state "... and [RFC9050] for protection against malicious PCEs should be used"?
【WAJ】Yes. Thanks for the clarification. Have updated the document accordingly.

Thirdly, was that last "should" intented to be lower-case (i.e., informative)?
【WAJ】s/SHOULD already.

Thanks,
Magnus


_______________________________________________
Pce mailing list -- pce@ietf.org
To unsubscribe send an email to pce-leave@ietf.org