Re: [secdir] Secdir review of draft-ietf-manet-nhdp-olsrv2-tlv-extension-01

"Dearlove, Christopher (UK)" <Chris.Dearlove@baesystems.com> Mon, 10 February 2014 16:07 UTC

Return-Path: <Chris.Dearlove@baesystems.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 382CB1A086D; Mon, 10 Feb 2014 08:07:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.448
X-Spam-Level:
X-Spam-Status: No, score=-7.448 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.548] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6Da0WqClUw4u; Mon, 10 Feb 2014 08:07:19 -0800 (PST)
Received: from ukmta3.baesystems.com (ukmta3.baesystems.com [20.133.40.55]) by ietfa.amsl.com (Postfix) with ESMTP id C21EB1A0694; Mon, 10 Feb 2014 08:07:18 -0800 (PST)
X-IronPort-AV: E=Sophos;i="4.95,818,1384300800"; d="scan'208";a="348072460"
Received: from unknown (HELO baemasodc005.greenlnk.net) ([10.108.52.29]) by Baemasodc001ir.sharelnk.net with ESMTP; 10 Feb 2014 16:07:17 +0000
From: "Dearlove, Christopher (UK)" <Chris.Dearlove@baesystems.com>
X-IronPort-AV: E=Sophos;i="4.95,818,1384300800"; d="scan'208";a="45726033"
Received: from glkxh0003v.greenlnk.net ([10.109.2.34]) by baemasodc005.greenlnk.net with ESMTP; 10 Feb 2014 16:07:17 +0000
Received: from GLKXM0002V.GREENLNK.net ([169.254.5.106]) by GLKXH0003V.GREENLNK.net ([10.109.2.34]) with mapi id 14.03.0174.001; Mon, 10 Feb 2014 16:07:17 +0000
To: Tero Kivinen <kivinen@iki.fi>, "iesg@ietf.org" <iesg@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>, "draft-ietf-manet-nhdp-olsrv2-tlv-extension.all@tools.ietf.org" <draft-ietf-manet-nhdp-olsrv2-tlv-extension.all@tools.ietf.org>
Thread-Topic: Secdir review of draft-ietf-manet-nhdp-olsrv2-tlv-extension-01
Thread-Index: AQHPJmk7TLKBdzx/bk2glfOcmVHZWJqupw1Q
Date: Mon, 10 Feb 2014 16:07:16 +0000
Message-ID: <B31EEDDDB8ED7E4A93FDF12A4EECD30D40252C32@GLKXM0002V.GREENLNK.net>
References: <21240.56492.25650.629460@fireball.kivinen.iki.fi>
In-Reply-To: <21240.56492.25650.629460@fireball.kivinen.iki.fi>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.109.62.6]
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Subject: Re: [secdir] Secdir review of draft-ietf-manet-nhdp-olsrv2-tlv-extension-01
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Feb 2014 16:07:21 -0000

Thanks you for your review and comments. IANA want a bit more clarity in their section, so we'll roll your nit in with that.

-- 
Christopher Dearlove
Senior Principal Engineer, Communications Group
Communications, Networks and Image Analysis Capability
BAE Systems Advanced Technology Centre
West Hanningfield Road, Great Baddow, Chelmsford, CM2 8HN, UK
Tel: +44 1245 242194 |  Fax: +44 1245 242124
chris.dearlove@baesystems.com | http://www.baesystems.com

BAE Systems (Operations) Limited
Registered Office: Warwick House, PO Box 87, Farnborough Aerospace Centre, Farnborough, Hants, GU14 6YU, UK
Registered in England & Wales No: 1996687


-----Original Message-----
From: Tero Kivinen [mailto:kivinen@iki.fi] 
Sent: 10 February 2014 14:06
To: iesg@ietf.org; secdir@ietf.org; draft-ietf-manet-nhdp-olsrv2-tlv-extension.all@tools.ietf.org
Subject: Secdir review of draft-ietf-manet-nhdp-olsrv2-tlv-extension-01

----------------------! WARNING ! ---------------------- This message originates from outside our organisation, either from an external partner or from the internet.
Consider carefully whether you should click on any links, open any attachments or reply.
Follow the 'Report Suspicious Emails' link on IT matters for instructions on reporting suspicious email messages.
--------------------------------------------------------

I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG.  These comments were written primarily for the benefit of the security area directors.  Document editors and WG chairs should treat these comments just like any other last call comments.

This document seems to fix some cases in the NHDP and OLSRv2 TLVs where the original document might have been considered saying that unknown values in the TLVs can be used as a reason to reject message.
This document makes it clear how unknown values in the TLVs needs to be processed. This document also creates several IANA registries for the TLV values and changes couple of the TLV values from numbers to bitfields (the existing values were already allocated so that the numbers can be parsed as bitfield).

Security considerations section mentions that as this does not really change the current implementations, it more or less describes how new extensions should be processed with implementations it does not add any new security considerations. New extensions might of course add new security considerations but those should be addressed in the documents which make those extensions.

The document is ready with nits.

Some nits:

In the IANA considerations section the IANA is used both in singular and plural, i.e. it says both "IANA is requested" and "IANA are requested". This should be fixed to say "IANA is requested". 
--
kivinen@iki.fi

********************************************************************
This email and any attachments are confidential to the intended
recipient and may also be privileged. If you are not the intended
recipient please delete it from your system and notify the sender.
You should not copy it or use it for any purpose nor disclose or
distribute its contents to any other person.
********************************************************************