Re: [secdir] Security directorate review of draft-ietf-pim-explicit-tracking

Magnus Nyström <magnusn@gmail.com> Thu, 19 December 2013 01:03 UTC

Return-Path: <magnusn@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 253DD1AD8CD for <secdir@ietfa.amsl.com>; Wed, 18 Dec 2013 17:03:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.699
X-Spam-Level:
X-Spam-Status: No, score=-1.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7Ec5SwCw3dVf for <secdir@ietfa.amsl.com>; Wed, 18 Dec 2013 17:03:27 -0800 (PST)
Received: from mail-wi0-x22f.google.com (mail-wi0-x22f.google.com [IPv6:2a00:1450:400c:c05::22f]) by ietfa.amsl.com (Postfix) with ESMTP id 4778F1AD7BE for <secdir@ietf.org>; Wed, 18 Dec 2013 17:03:27 -0800 (PST)
Received: by mail-wi0-f175.google.com with SMTP id hi5so6140472wib.14 for <secdir@ietf.org>; Wed, 18 Dec 2013 17:03:25 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:date:message-id:subject:from:to:cc:content-type; bh=aRlFkjKeLJnbw2Qoz9L8+ufwtNSDYIxB5HIZMSCfJGc=; b=HwwrFbFAY9AbhfpWaHykCWPg9nwhbg53sXLcB3pGw3gRCDu36Awm2xZ28h7FfJWzIN qQsSkAbbeqz1QfX3HjMH8V2zv71kdeYsmvKeOZtyjbhahwhUsDs2n31TowC7i3AVsNSZ b41JFm+uC4O2c6wsQE1Lw5fJrAb6TDLpaKnf9hqewKzbmqRPxprO5Xfyu31DK31TuFZb KLfopalKAEqkpKI/yiQzL7z59niBhNAfl4hVi7PJUH7WfdF/O1M8VJcvhMN8J+e+H68e UnEXzha3biK3TEYgtADTVbkP2quBHGjoy/CpBfSm/VFkoNkoQnfB7txOT6hF6Vmgthvr kM8Q==
MIME-Version: 1.0
X-Received: by 10.180.95.162 with SMTP id dl2mr308035wib.17.1387415005227; Wed, 18 Dec 2013 17:03:25 -0800 (PST)
Received: by 10.180.36.78 with HTTP; Wed, 18 Dec 2013 17:03:25 -0800 (PST)
Date: Wed, 18 Dec 2013 17:03:25 -0800
Message-ID: <CADajj4b0KsPi-AthWSyiZ32bb1fkzCjwkW2kCAb6ZBnpkruR=A@mail.gmail.com>
From: Magnus Nyström <magnusn@gmail.com>
To: "adrian@olddog.co.uk" <adrian@olddog.co.uk>
Content-Type: multipart/alternative; boundary="f46d0444e9838aef5304edd8ba01"
Cc: draft-ietf-pim-explicit-tracking@tools.ietf.org, "secdir@ietf.org" <secdir@ietf.org>
Subject: Re: [secdir] Security directorate review of draft-ietf-pim-explicit-tracking
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Dec 2013 01:03:29 -0000

All, this is just to confirm - in time for the IESG telechat tomorrow -
that I am happy with the updates the author made in draft version -09 to
the Security Considerations section based on our discussion.
Thanks,
/Magnus

On Mon, Nov 11, 2013 at 11:40 AM, Adrian Farrel <adrian@olddog.co.uk> wrote:

> Authors,
>
>
>
> Could you please engage with Magnus to either address his concerns in a
> new revision, or explain to him why that would not be necessary/appropriate.
>
>
>
> Thanks,
>
> Adrian
>
>
>
> *From:* iesg-bounces@ietf.org [mailto:iesg-bounces@ietf.org] *On Behalf
> Of *Magnus Nyström
> *Sent:* 08 November 2013 04:16
> *To:* secdir@ietf.org; draft-ietf-pim-explicit-tracking@tools.ietf.org
> *Cc:* iesg@ietf.org
> *Subject:* Security directorate review of
> draft-ietf-pim-explicit-tracking [Was: Re: Security directorate reveiw of
> draft-asaeda-mboned-explicit-tracking
>
>
>
>
>
> [I did it again ... Sorry about the incorrect Subject: title, I used the
> original draft name, the current name is of course
> draft-ietf-pim-explicit-tracking.]
>
>
>
> On Thu, Nov 7, 2013 at 8:13 PM, Magnus Nyström <magnusn@gmail.com> wrote:
>
> I have reviewed this document as part of the security directorate's
> ongoing effort to review all IETF documents being processed by the IESG.
> These comments were written primarily for the benefit of the security area
> directors. Document editors and WG chairs should treat these comments just
> like any other last call comments.
>
> This document describes a tracking function for multicast routers and
> proxies, intended to reduce latencies and network traffic, among other
> things.
>
> The document seems well written but the security considerations sections
> makes vague references to "serious threats" that may be introduced by
> malicious hosts on the network yet only states that "abuse" can be
> mitigated by limiting the amount of information a router can store (which
> seems like a given anyway?). It would be good if the document enumerated
> the "serious threats" and their mitigations.
>
>
> -- Magnus
>
>
>
>
> --
> -- Magnus
>



-- 
-- Magnus