Re: [secdir] secdir review of draft-ietf-ospf-node-admin-tag-05

Benjamin Kaduk <kaduk@MIT.EDU> Wed, 14 October 2015 02:30 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D13A01AD10A; Tue, 13 Oct 2015 19:30:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 92g_XvKXLOAL; Tue, 13 Oct 2015 19:30:52 -0700 (PDT)
Received: from dmz-mailsec-scanner-4.mit.edu (dmz-mailsec-scanner-4.mit.edu [18.9.25.15]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 718801AD0CB; Tue, 13 Oct 2015 19:30:51 -0700 (PDT)
X-AuditID: 1209190f-f799c6d000001933-45-561dbe59578b
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-4.mit.edu (Symantec Messaging Gateway) with SMTP id 7D.B8.06451.95EBD165; Tue, 13 Oct 2015 22:30:49 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id t9E2UfVR002223; Tue, 13 Oct 2015 22:30:41 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t9E2Ubr0002790 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 13 Oct 2015 22:30:39 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t9E2UaQ3020069; Tue, 13 Oct 2015 22:30:36 -0400 (EDT)
Date: Tue, 13 Oct 2015 22:30:36 -0400 (EDT)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: bruno.decraene@orange.com
In-Reply-To: <27748_1444745556_561D1154_27748_5857_1_53C29892C857584299CBF5D05346208A0F677EDF@OPEXCLILM21.corporate.adroot.infra.ftgroup>
Message-ID: <alpine.GSO.1.10.1510132230020.26829@multics.mit.edu>
References: <alpine.GSO.1.10.1510091159450.26829@multics.mit.edu> <27748_1444745556_561D1154_27748_5857_1_53C29892C857584299CBF5D05346208A0F677EDF@OPEXCLILM21.corporate.adroot.infra.ftgroup>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFupjleLIzCtJLcpLzFFi42IRYrdT143cJxtmcOSkjsWPHXOYLX6/2sJu MePPRGaLDwsfsljceLSX2YHVY8mSn0we15uusnu0PDvJFsAcxWWTkpqTWZZapG+XwJXxbPEF loJpLBXPvuc3MLYydzFycEgImEhMXyHTxcgJZIpJXLi3nq2LkYtDSGAxk8T9hnNMEM5GRokd 76awQDiHmCQOfJkPlWlglDizo5cVpJ9FQFvi8Zw/7CA2m4CKxMw3G9lAbBEBWYk/RxsZQRqY Be4xSuy7vxqsQVjAXuJIxzEWEJtToJNRYn1HLIjNK+AocaBlEzvEhn2MEt+mLWIGSYgK6Eis 3j+FBaJIUOLkzCdgNrOAlsTy6dtYJjAKzkKSmoUktYCRaRWjbEpulW5uYmZOcWqybnFyYl5e apGuiV5uZoleakrpJkZQUHNK8u9g/HZQ6RCjAAejEg9vxmrZMCHWxLLiytxDjJIcTEqivHl7 gEJ8SfkplRmJxRnxRaU5qcWHGCU4mJVEeFOXAOV4UxIrq1KL8mFS0hwsSuK8m37whQgJpCeW pGanphakFsFkZTg4lCR4c/YCNQoWpaanVqRl5pQgpJk4OEGG8wANbwWp4S0uSMwtzkyHyJ9i 1OVY8OP2WiYhlrz8vFQpcV4lkCIBkKKM0jy4OeBktJtJ9RWjONBbwryOIFU8wEQGN+kV0BIm oCVG7FIgS0oSEVJSDYxh66N+XFsUFPIscJ6t5Ky7bSukmPRU80/fLNnHfNLLLza/w1I4QrT2 qaWI4gHPBafj0hySJ52IvbdIv6lqxf1Xk3pZD/QvL21pqSx69JXtZ9M1E5G1r89wm1S/dQ45 dIvjoLnbBRVFp2fL7v5xOBMylbFCO+7LQd6ucwvNgm/EZIR+NxA+na7EUpyRaKjFXFScCAA6 pbFSIQMAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/secdir/FT81G3Iml0J1alWq5wdVaBYXiao>
Cc: "draft-ietf-ospf-node-admin-tag.all@ietf.org" <draft-ietf-ospf-node-admin-tag.all@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>, Shraddha Hegde <shraddha@juniper.net>, "iesg@ietf.org" <iesg@ietf.org>
Subject: Re: [secdir] secdir review of draft-ietf-ospf-node-admin-tag-05
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Oct 2015 02:30:55 -0000

On Tue, 13 Oct 2015, bruno.decraene@orange.com wrote:

> Hi Ben,
>
>
>
> > In section 4.5, I do not see that the constraint "Traffic from A nodes to
>
> > I nodes must not go through R and T nodes" can be satisfied for the
>
> > leftmost pair of A nodes.
>
>
>
>
>
> Thanks for the careful review.
>
> My mistake. I missed the left part of the network.
>
> I see 2 options:
>
> a) add some network topology on the left part
>
> b) remove the leftmost pair of A nodes.

Option 'a' sounds good to me.

-Ben