[secdir] sec-dir review of draft-ietf-trill-transport-over-mpls-07

Derek Atkins <derek@ihtfp.com> Thu, 22 February 2018 22:00 UTC

Return-Path: <derek@ihtfp.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AF1A812946D; Thu, 22 Feb 2018 14:00:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.989
X-Spam-Level:
X-Spam-Status: No, score=-1.989 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, T_SPF_PERMERROR=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ihtfp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id t5-_vabQqHRl; Thu, 22 Feb 2018 14:00:17 -0800 (PST)
Received: from mail2.ihtfp.org (MAIL2.IHTFP.ORG [204.107.200.7]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ADDF212420B; Thu, 22 Feb 2018 14:00:17 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mail2.ihtfp.org (Postfix) with ESMTP id 8778DE2087; Thu, 22 Feb 2018 17:00:16 -0500 (EST)
Received: from mail2.ihtfp.org ([127.0.0.1]) by localhost (mail2.ihtfp.org [127.0.0.1]) (amavisd-maia, port 10024) with ESMTP id 25121-10; Thu, 22 Feb 2018 17:00:15 -0500 (EST)
Received: from securerf.ihtfp.org (IHTFP-DHCP-250.IHTFP.ORG [192.168.248.250]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mocana.ihtfp.org", Issuer "IHTFP Consulting Certification Authority" (verified OK)) by mail2.ihtfp.org (Postfix) with ESMTPS id 3FE79E2053; Thu, 22 Feb 2018 17:00:15 -0500 (EST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ihtfp.com; s=default; t=1519336815; bh=fWcDTxOEuUwkfLEm5qJ7UMZG7UEStFEnoOVCoHTbHxE=; h=From:To:Cc:Subject:Date; b=q5WFeS2D35FcD6mZivDxRPMByXc0CBrBJlhfX3W2gzlLZGAcPzt+qZgiKR13doCtP bl29VsxW9lQpESazd9uqoceACajQHacSIIBZolDNyWhFETDx8aSzcy0WWBeszuRmh6 /rpG1sCTb/A+fI9P+DR/V1vXWmBwo1HGwf85WnxA=
Received: (from warlord@localhost) by securerf.ihtfp.org (8.15.2/8.15.2/Submit) id w1MM0EsL008569; Thu, 22 Feb 2018 17:00:14 -0500
From: Derek Atkins <derek@ihtfp.com>
To: iesg@ietf.org, secdir@ietf.org
Cc: trill-chairs@ietf.org, lucyyong@gmail.com, d3e3e3@gmail.com, kingstonsmiler@gmail.com, mohammed.umair2@gmail.com
Date: Thu, 22 Feb 2018 17:00:14 -0500
Message-ID: <sjmy3jkit1t.fsf@securerf.ihtfp.org>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/25.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
X-Virus-Scanned: Maia Mailguard 1.0.2a
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/8nbgGLuZISfwn9_mIHIuwrQwWUg>
Subject: [secdir] sec-dir review of draft-ietf-trill-transport-over-mpls-07
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Feb 2018 22:00:18 -0000

Hi,

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written with the intent of improving
security requirements and considerations in IETF drafts.  Comments
not addressed in last call may be included in AD reviews during the
IESG review.  Document editors and WG chairs should treat these
comments just like any other last call comments.

Summary:

Ready to publish (with minor edits).

Details:

There is a typo in Figure 2 on page 7 where you have two instances of
"Tenant2 Site 2".  I suspect that RBat2 should be labeled Tenant2 Site
1.  The same mistake is in Figure 4 on page 11.

-derek

-- 
       Derek Atkins                 617-623-3745
       derek@ihtfp.com             www.ihtfp.com
       Computer and Internet Security Consultant