Re: [secdir] Sector Review: draft-ietf-ospf-te-metric-extensions-09

Ben Laurie <benl@google.com> Mon, 05 January 2015 21:18 UTC

Return-Path: <benl@google.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DE1721A8A90 for <secdir@ietfa.amsl.com>; Mon, 5 Jan 2015 13:18:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.389
X-Spam-Level:
X-Spam-Status: No, score=-1.389 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NC26tXAdoA0c for <secdir@ietfa.amsl.com>; Mon, 5 Jan 2015 13:18:43 -0800 (PST)
Received: from mail-qc0-x233.google.com (mail-qc0-x233.google.com [IPv6:2607:f8b0:400d:c01::233]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 72CDB1A8A82 for <secdir@ietf.org>; Mon, 5 Jan 2015 13:18:43 -0800 (PST)
Received: by mail-qc0-f179.google.com with SMTP id c9so16280545qcz.10 for <secdir@ietf.org>; Mon, 05 Jan 2015 13:18:42 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding; bh=vqXf3/7DLU9RAOyir0v5ZcLCm1/qdLXKT7FlAh6NFYM=; b=WmGjyIeNEc+uVq+lmLBDvHy5tFkIhRU/gNla0P2d9s4T6Nq5m2R9XqCmAIqtFSUYwV ruk2Ijgnt2NATLeBBv0U2z4mxDEjr8J8sALscqc/0Ldik68eCxgrAXP62dSYqvNd1r6h uBqddI9GiWwKRC4OqhQZ+tP9bAqLYWqu0ubtuVQ2egQWk3jYxOjsk5yeT6N5fvPpO8ia LeOX2xGf3ZrGl1nhEF5zBT3Sj6+CUsBgzsPv2GkkxG95HNOrgjv91DC7+CBt0JurzluQ P/T3wZXUFi2qbyCHWH+l43QgH6KZfuJkwWWMDWCGcUOs9PPQLHHv3nooMUbddaocqk49 U3Ew==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type :content-transfer-encoding; bh=vqXf3/7DLU9RAOyir0v5ZcLCm1/qdLXKT7FlAh6NFYM=; b=VpQnahSs38foyyA2F1DVxNtsdkdJ54yZcJe/Bz8PZE9MWs+5+MBtIht+5p2XTVd842 kWDAtlQYeeYnTUaLhala76dZxvDBGlNHMCkVtv4TaJz86pLa78tBGQtTWTmu3f6KovyX SBUJPe1pCQpMcZSy2K0DBnzlz7E1Wd4La55GPDH8nI2xYYCVz5f737RFycWe4/qbxC2A l6CoFxZb7s+gA2bSWi3k95uOQtsoK3E6WSbkLI4YoGNv7EtFlPXI+t/7bqFYp0ryQ8ZW jkMevh/oiI3TUYqhLuBV7kEilq9i7vLC9RXtuWaqwWYcM/EVbR1XvP8hxv1VUMJmT+Tm PL/Q==
X-Gm-Message-State: ALoCoQntfv9lYPkojp36ASOFqD06ctVo4pksAi/C9tzG535tvCoytCXYLkkC9CD966Dmvptd60Tl
MIME-Version: 1.0
X-Received: by 10.229.93.132 with SMTP id v4mr148083065qcm.27.1420492722663; Mon, 05 Jan 2015 13:18:42 -0800 (PST)
Received: by 10.229.183.201 with HTTP; Mon, 5 Jan 2015 13:18:42 -0800 (PST)
In-Reply-To: <CABrd9STqBsPQpp_N751ybF_0uF8C3MGG3hKhzoPCBO_pgoCULw@mail.gmail.com>
References: <4E0F5009-4811-4FFE-AA26-ECFAC2398101@ogud.com> <m28uhj2wxg.wl%randy@psg.com> <96B524C4-B2E8-443E-871D-60B5FCD2F44A@ogud.com> <m2bnmdym1g.wl%randy@psg.com> <CABrd9STqBsPQpp_N751ybF_0uF8C3MGG3hKhzoPCBO_pgoCULw@mail.gmail.com>
Date: Mon, 05 Jan 2015 21:18:42 +0000
Message-ID: <CABrd9SR5u3uWf+BRX1xpLS4b9-bcrT_M-ECz2u2yAOe1dLxnqw@mail.gmail.com>
From: Ben Laurie <benl@google.com>
To: Randy Bush <randy@psg.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: http://mailarchive.ietf.org/arch/msg/secdir/DDXOMKUtzsmokbwP_kacKuYv1FI
Cc: draft-ietf-ospf-te-metric-extension@tools.ietf.org, ietf <ietf@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>
Subject: Re: [secdir] Sector Review: draft-ietf-ospf-te-metric-extensions-09
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Jan 2015 21:18:45 -0000

On 5 January 2015 at 21:18, Ben Laurie <benl@google.com> wrote:
> On 5 January 2015 at 21:06, Randy Bush <randy@psg.com> wrote:
>>>>> The document contains no issues from a security perspective as it is
>>>>> only creating LSA’s for new types of route selection metrics, time
>>>>> instead of network hops.
>>>>
>>>> and the new lsas could not be used in path shortening attacks, right?
>>>
>>> this document only defines the format of the LSA’s it does
>>> not talk about processing by the routing engines.
>>
>> so the secdir sees no need to warn about it.  got it.  </sarcasm>
>
> If secdir is going to warn about it through this process, then shortly

Good grief. Surely.

> the right place to do that is in the comments on the document that
> does talk about processing by the routing engines?