[secdir] Secdir review of draft-ietf-pals-p2mp-pw-03

Tero Kivinen <kivinen@iki.fi> Thu, 24 August 2017 07:16 UTC

Return-Path: <kivinen@iki.fi>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 23755132BE7; Thu, 24 Aug 2017 00:16:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.121
X-Spam-Level:
X-Spam-Status: No, score=-1.121 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_NEUTRAL=0.779] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id D5m4MQO3ct0S; Thu, 24 Aug 2017 00:16:45 -0700 (PDT)
Received: from mail.kivinen.iki.fi (fireball.acr.fi [212.16.101.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ED8DC132B9C; Thu, 24 Aug 2017 00:16:44 -0700 (PDT)
Received: from fireball.acr.fi (localhost [127.0.0.1]) by mail.kivinen.iki.fi (8.15.2/8.15.2) with ESMTPS id v7O7GgE1004496 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Thu, 24 Aug 2017 10:16:42 +0300 (EEST)
Received: (from kivinen@localhost) by fireball.acr.fi (8.15.2/8.14.8/Submit) id v7O7GfOp027226; Thu, 24 Aug 2017 10:16:41 +0300 (EEST)
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Message-ID: <22942.32089.500600.506465@fireball.acr.fi>
Date: Thu, 24 Aug 2017 10:16:41 +0300
From: Tero Kivinen <kivinen@iki.fi>
To: iesg@ietf.org, secdir@ietf.org, draft-ietf-pals-p2mp-pw.all@tools.ietf.org
X-Edit-Time: 11 min
X-Total-Time: 13 min
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/ga2pIVcGw9WEgBX5MXA9MCmSs_s>
Subject: [secdir] Secdir review of draft-ietf-pals-p2mp-pw-03
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Aug 2017 07:16:47 -0000

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written primarily for the benefit of the
security area directors.  Document editors and WG chairs should treat
these comments just like any other last call comments.

This document describes the mechanims to signal point-to-multipoint
pseudowires using LDP. The security considerations section simply
points to the RFC4447bis (i.e., RFC8077) saying that security
mechanisms described there are adequate.

On the other hand RFC8077, says that LDP MD5 authentication key option
as described in the section 2.9 of RFC5036 MUST be implemented. The
section 2.9 of RFC5036 describes TCP MD5 signature option for LDP.
This might have been adequate security for some protocol in 2007 (when
RFC5036 was published, altought MD5 was already then known to be
broken), but it IS NOT adequate security in 2017.

I understand that this document is not really the one supposed to
update the security option for the LDP, but there is
draft-ijln-mpls-rfc5036bis which is moving LDP to internet standard
still trying to keep the same broken MD5 based security in it. I think
this document should include note saying, that security of the RFC5036
is no longer adequate for any use because it uses broken security
protocol, but there is nothing better out there yet (or is there, I do
not know enough of the LDP to know that), and perhaps point to the
rfc5036bis also in hopes that it might some day fix the security of
the LDP.

I think this document (or whole PW and LDP system) has issues that
needs to be fixed before it can be published.
-- 
kivinen@iki.fi