[secdir] Secdir review of draft-ietf-mpls-mldp-in-band-signaling-07

Catherine Meadows <catherine.meadows@nrl.navy.mil> Mon, 05 November 2012 21:23 UTC

Return-Path: <catherine.meadows@nrl.navy.mil>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost []) by ietfa.amsl.com (Postfix) with ESMTP id 2E9CE21F8487; Mon, 5 Nov 2012 13:23:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([]) by localhost (ietfa.amsl.com []) (amavisd-new, port 10024) with ESMTP id V3Jxac0pBgM4; Mon, 5 Nov 2012 13:23:11 -0800 (PST)
Received: from fw5540.nrl.navy.mil (fw5540.nrl.navy.mil []) by ietfa.amsl.com (Postfix) with ESMTP id 6364721F845D; Mon, 5 Nov 2012 13:23:09 -0800 (PST)
Received: from chacs.nrl.navy.mil (sun1.fw5540.net []) by fw5540.nrl.navy.mil (8.13.8/8.13.6) with ESMTP id qA5LN7Eq009698; Mon, 5 Nov 2012 16:23:08 -0500 (EST)
Received: from chacs.nrl.navy.mil (sun1 []) by chacs.nrl.navy.mil (8.13.8/8.13.6) with SMTP id qA5LN6Ug001554; Mon, 5 Nov 2012 16:23:06 -0500 (EST)
Received: from siduri.fw5540.net ([]) by chacs.nrl.navy.mil (SMSSMTP with SMTP id M2012110516230521045 ; Mon, 05 Nov 2012 16:23:05 -0500
From: Catherine Meadows <catherine.meadows@nrl.navy.mil>
Content-Type: multipart/alternative; boundary=Apple-Mail-23-181231044
Date: Mon, 5 Nov 2012 16:23:05 -0500
Message-Id: <E8F345E2-5E4B-42CC-8418-E79F434171EA@nrl.navy.mil>
To: iesg@ietf.org, secdir@ietf.org, draft-ietf-mpls-mldp-in-band-signaling.all@tools.ietf.org
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
Subject: [secdir] Secdir review of draft-ietf-mpls-mldp-in-band-signaling-07
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Nov 2012 21:23:12 -0000

I have reviewed this document as part of the security directorate's 
ongoing effort to review all IETF documents being processed by the 
IESG.  These comments were written primarily for the benefit of the 
security area directors.  Document editors and WG chairs should treat 
these comments just like any other last call comments.

This document describes procedures for splicing IP multicast trees, constructed by Protocol
Independent Multicast, together with multipoint Labeled Switched Paths (LSPs)  in MPLS domains in Multipoint LDP (mLDP)
these can be created.   In particular,
it describes a way of transmitting the necessary information about which end-user packets are associated with
which LSPs in the "opaque value" field of an mLDP Forwarding Equivalence Class (FEC) element.  Previously, such
information had been sent in out-of-band protocols such as  PIM and BGP. 

This document mainly concerns ways of representing the different kinds of maps between end-user packets and LSPs
in FECs.  Thus, the only security considerations are inherited from the base LDP specification, as the authors point out.
I believe that this use of mLDP FECs is  appropriate from a security point of view, because the information being transmitted is for use by mLDP.
Indeed, I would argue that reducing complexity by no longer using an out-of-band protocol improves security.

Catherine Meadows
Naval Research Laboratory
Code 5543
4555 Overlook Ave., S.W.
Washington DC, 20375
phone: 202-767-3490
fax: 202-404-7942
email: catherine.meadows@nrl.navy.mil