[secdir] SECDIR review of draft-ietf-teas-pce-native-ip-14

Donald Eastlake <d3e3e3@gmail.com> Tue, 08 December 2020 05:57 UTC

Return-Path: <d3e3e3@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 40EF33A07D1; Mon, 7 Dec 2020 21:57:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.838
X-Spam-Level:
X-Spam-Status: No, score=-1.838 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_FREEMAIL_DOC_PDF=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VpQTI-sTeA_6; Mon, 7 Dec 2020 21:57:51 -0800 (PST)
Received: from mail-io1-xd31.google.com (mail-io1-xd31.google.com [IPv6:2607:f8b0:4864:20::d31]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 361AC3A07B3; Mon, 7 Dec 2020 21:57:48 -0800 (PST)
Received: by mail-io1-xd31.google.com with SMTP id n4so15806542iow.12; Mon, 07 Dec 2020 21:57:48 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to:cc; bh=7BW3kKkznMw3z7qdnFoeCkOx5GpJflhChuqkA4KfcfM=; b=qoA2ARV5ybPul5waj+hNRK9pHUZJa9umUGf6b78wXExw8zGNaS9Rg+FMQwMqehRaCV HgZfXQXHtXAGq/fCHHR8n/R4+khJSpyVGTki0bmHRifCIikas+RqUa8STcm1AzdM6Kf/ Ke4z6QqxBbGZgseVpBBnNs8c8SLWrGm9p2x3YmYx5JjXaLxdPxch9u433eh8uADTVe17 HLilTys4w4QmZQjZAKqs/hh6kZtqehvczdYWmIqgGI2wRXig0HPKO0tSZkMqS6mYubjC L9dYAttdNuiOGuNdJ0K7A5ibKZALjNPLWoVxvDP4g7T2bsIkbeH19THVxTPM9zwdPe9w /l/w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to:cc; bh=7BW3kKkznMw3z7qdnFoeCkOx5GpJflhChuqkA4KfcfM=; b=tmn6tn5OayP1/dnV6Fv0aRmjDD4I7MIMlC32CXGjHI9wE3N1O9cXoI0zLwjbUW5oMp zvyZ94+KCF9aq9cc/eDTGI8TxtkhcmSDm/GVHdSTgR6rwSrEAgOj8V9QrNXk5H71SQrm OtbjSc1wrOZ0pZfNbZSuW1BY9iWn86xJLt1JGNkXAz0UsFMIVQGiJyqXj0g/6LyHpIoC 9k8aQ8XYI/7knwZlPEXWLDZBM1jDx6lFnSzAKnRwuKGUTrk50TkovSdKOQSI6cWxE4nP Zj6GllqUqTskOlMJbPQdeVYWY+/rdd/+D3+Pi+EhrfEe0iKtP8QkU63CuF09W/LKwkkA p1+g==
X-Gm-Message-State: AOAM5336RxfieGA5jrjE7bc6P9BcXk+jJdU0QIq8x6Z/qRqZfkzBOrPl acdTuWlzl8chlzRBn7KdXY5FE40pijO+71CyCbZZMJzeZ5O07w==
X-Google-Smtp-Source: ABdhPJzsASccBq00QzdSJlPKk9NwVGwNPzDCEkd4OH249sjGjztVDOTpCgex+BvnnqmzfDabxnmeTY0Z6yN5NoE4qAo=
X-Received: by 2002:a05:6602:13c5:: with SMTP id o5mr22472626iov.46.1607407066579; Mon, 07 Dec 2020 21:57:46 -0800 (PST)
MIME-Version: 1.0
From: Donald Eastlake <d3e3e3@gmail.com>
Date: Tue, 08 Dec 2020 00:57:33 -0500
Message-ID: <CAF4+nEFFo+EwawOfEaS4mWnVzcokKOQw0Mt6qp240sMy9NKzow@mail.gmail.com>
To: "iesg@ietf.org" <iesg@ietf.org>, draft-ietf-teas-pce-native-ip.all@ietf.org
Cc: secdir <secdir@ietf.org>, last-call@ietf.org
Content-Type: multipart/mixed; boundary="00000000000036b4e005b5ed9f95"
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/GkaNkma1cNdFsAbCDN2Zsr0sLVg>
Subject: [secdir] SECDIR review of draft-ietf-teas-pce-native-ip-14
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Dec 2020 05:57:54 -0000

I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG.  Document
editors and WG chairs should treat these comments just like any other last
call comments.

The summary of the review is Ready with Issues.

Security:
This is a very high level Informational document about a general method of
traffic engineering using multiple BGP sessions and PCE. The Security
Considerations section is adequate except that I would recommend adding a
reference for BGP security, perhaps to RFC 7454.

Other Issues:
The title of the document doesn't really make it clear what it is about and
does not spell out some acronyms. I suggest the following:

Path Computation Element (PCE) Traffic Engineering (TE) in Native IP
NetworkNetworks


Editorial:
There are a number of editorial/typo issues including the curious lack of
any expansion or definition for the first three acronyms listed in Section
2 on Terminology and what appears to be a line sliced off the bottom of
Figure 3. Also, I think a reference should be given where BGP Flowspec is
mentioned in Section 7.1, presumably to the rfc5575bis draft. See attached
for detailed change suggestions in MS Word with tracked changes and,
alternatively, as a PDF thereof.

Thanks,
Donald
===============================
 Donald E. Eastlake 3rd   +1-508-333-2270 (cell)
 2386 Panoramic Circle, Apopka, FL 32703 USA
 d3e3e3@gmail.com