[secdir] SECDIR review of draft-ietf-radext-reverse-coa
Donald Eastlake <d3e3e3@gmail.com> Wed, 06 August 2025 22:14 UTC
Return-Path: <d3e3e3@gmail.com>
X-Original-To: secdir@mail2.ietf.org
Delivered-To: secdir@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 9B2D450D6968; Wed, 6 Aug 2025 15:14:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.849
X-Spam-Level:
X-Spam-Status: No, score=-1.849 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rSfm_2Sh9Xmc; Wed, 6 Aug 2025 15:14:09 -0700 (PDT)
Received: from mail-qk1-x733.google.com (mail-qk1-x733.google.com [IPv6:2607:f8b0:4864:20::733]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4905F50D695E; Wed, 6 Aug 2025 15:14:06 -0700 (PDT)
Received: by mail-qk1-x733.google.com with SMTP id af79cd13be357-7e811828b2fso50476085a.0; Wed, 06 Aug 2025 15:14:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1754518445; x=1755123245; darn=ietf.org; h=cc:to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=afyoXZ0EWSqYoBmeglBfwCKCfooNNLJ/wBmK7aR9WrY=; b=mrIWvGIfNOD4uoXW+seOILKWkMIt54AWRoNGVur2WlI7c3jx0HYWhJtVIU2t6ZyR3q EsNhH7mlUUrTsUdXEHeElKZTgzUwIwZQXu8+bFTN94o1PtPHbK1JYk/z24Wk4HCM3J+E uRd7Z3BrQez1rSnpt6LP/Raf8cdwKoQlzn8VHkvLzUBjK94u4xGsEccx3DiCt6XtGlLs ugyRcneRvWoCHCWo7vNhrEOwZ2Hk/ypU4ZSwB/rkZdVE8XMGDjpK2dVBxoFUJ8NO/n0e lcViudfOY0F9XvnUK+lYl49BL/5wYYxHhWq6cdk1TkoThHRy3m4MEK8gKB9wS/Qi68oo UTvw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1754518445; x=1755123245; h=cc:to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=afyoXZ0EWSqYoBmeglBfwCKCfooNNLJ/wBmK7aR9WrY=; b=FecQ3QjeoCyb6UwqjllWGmkILsVwlv30US4Zh1lJRtdgzLJvS92UvMlz5d8R74QrjF fv7HzREb53cjxpKsJ5OTGydSfwBsDnWx3pP78pKwG3lxXQ4MSM1NCtTWoDJhQauqTQ5r i7Za/2teNK8Onbqns5bjYQCQdE5BBxIvHtwqqxY2phMCG81Pfd2eI4Rb2svtoAOPxIcB VeHLd1hdPv8lBlr2BuSD79S4P2duz1IuHDjtd5qWPKDLVanNlbO2Vd4+3WVt8XiHWSrY XmvY/VbAIDdl3O5OAfDXhGWLfkBC5N/DCPYfmImgblrrXVZo4sv0Fa4K+vAOuyIY+GB2 n7hg==
X-Forwarded-Encrypted: i=1; AJvYcCU830iZP7JnPHrMQF/OR+IazY+axnvvl+SJYm+JzXiZQkKbSUmFsS8XGW/JqGNDmB8jsm9HsKPKFMe2ifuWW193XMKr0b5QpZkr/CbR7hoRaDA=@ietf.org
X-Gm-Message-State: AOJu0YxfKuQ2sUPIRdU6Azy3W9Xj7oK+2HDJpRICnmrQR86Z53C2wnb7 +aakfEB0uJZWbdBUbtbzRMhkQVOV88e8Kb94/0WzJOa9Y8hUnIdxjKxFhihgVcqibScVapT4ZvS 7EPp1bGHhgx+NIHwNO+HZxcrNTYiW3084GVqq
X-Gm-Gg: ASbGncthne+btDYwQCF44f5HVh1CEJpoPbNayWgnAKp8JmVrWw8UNW1E4wy7LRbNlbN PepjtNPx+RW5O7131DqSWai7LDL9M9vpkknIGaS9MtGeaMQrHXEQe6HOhj49iTf2Dk9NzH+vshq bgcPoHHOvjo+E3zRRIyLm//6yu2AHrS+jVJ1jOh0G7iIr1fg0dAc8QYto6+Gtch0Pm6lW1y9klM lcM2D7Cj52UPJfM
X-Google-Smtp-Source: AGHT+IEi5rhyOJ8Bh5IHcLqnjAYAZKdh5+w3AIrpFb7KEPTHgcJv1wyjFgfo3+6W5q2/4uStEi+9XnVS4sOWsunYobE=
X-Received: by 2002:a05:620a:4043:b0:7e3:28f3:899 with SMTP id af79cd13be357-7e814e7c586mr771213485a.39.1754518445366; Wed, 06 Aug 2025 15:14:05 -0700 (PDT)
MIME-Version: 1.0
From: Donald Eastlake <d3e3e3@gmail.com>
Date: Wed, 06 Aug 2025 18:13:54 -0400
X-Gm-Features: Ac12FXxiDD0PrpUsrR9y6w4FEGU9VhNc8g3y7gV7pFOCd5OVqZ_wBRThv0_PwVM
Message-ID: <CAF4+nEHKZuaX9oCjbXusep4uUd=weaJXTFpfXcog-A4h04ETXA@mail.gmail.com>
To: "iesg@ietf.org" <iesg@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Message-ID-Hash: EXKN6XVT4SMIN2P3WEEPW6WV2FNPSE4C
X-Message-ID-Hash: EXKN6XVT4SMIN2P3WEEPW6WV2FNPSE4C
X-MailFrom: d3e3e3@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-secdir.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: secdir <secdir@ietf.org>, draft-ietf-radext-reverse-coa.all@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [secdir] SECDIR review of draft-ietf-radext-reverse-coa
List-Id: Security Area Directorate <secdir.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/q0wZsCi_5dMaQDM3uT1KJI7NnYc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Owner: <mailto:secdir-owner@ietf.org>
List-Post: <mailto:secdir@ietf.org>
List-Subscribe: <mailto:secdir-join@ietf.org>
List-Unsubscribe: <mailto:secdir-leave@ietf.org>
I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. The summary of the review is Almost Ready This is a simple draft improving the standardization of how to send "reverse path" RADIUS CoA and Disconnect packets from a RADIUS server, possibly via proxies, to a NAS. I note that it is very late in the process and this document is in IESG Consideration. I have not looked at any of the AD reviews so this may be a fresh review. Security -------- The Security Considerations Section 8 just says (in different words) that the document improves security by standardizing reverse paths for CoA-Request and Disconnect-Request packets. I would add a little bit about why, if there is a need to disconnect or change authentication, it can be a security problem if you cannot do that. Also, Section 4 just says that in various cases of misconfiguration CoA (which is defined to also include Disconnect in this document) packets will not flow and says this causes no further issues. I suggest "there will be no other issues with this misconfiguration" -> "which may reduce security (see Section 8)". Nits / trivial issues --------------------- Section 1, 2nd and 3rd paragraphs: Perhaps these should be merged or something as on initial reading it was not clear to me that the "Section 3.4" in the 3rd paragraph was that section in RFC 6614 which is referenced in the 2nd paragraph. Section 1, 3rd paragraph: Should "which types of packets are supported on a server" be "which types of packets it supports"? Section 3: "a configuration and signalling," -> "a configuration and signalling method," Section 3 says there are two additions. These are then discussed in Section 4 and 5 but there is no tie between those sections and Section 3. Suggest adding at the end of Section 3: "These additions are discussed in Sections 4 and 5 respectively." Section 5.1, 2nd paragraph: "have the choice more than one" -> "have a choice of more than one" Section 5.2, 2nd paragraph: the server's connection choice is not unconstrained. "chooses one connection" -> "chooses one of these connections" Section 6.3, I didn't review Section 6 very closely but it seems odd that in Section 6.3 there is a raw direct reference rather than indirecting through the Informational References section. But, since Section 6 is going away, it does not matter much. Thanks, Donald =============================== Donald E. Eastlake 3rd +1-508-333-2270 (cell) 2386 Panoramic Circle, Apopka, FL 32703 USA d3e3e3@gmail.com
- [secdir] SECDIR review of draft-ietf-radext-rever… Donald Eastlake
- [secdir] Re: SECDIR review of draft-ietf-radext-r… Alan DeKok
- [secdir] Re: SECDIR review of draft-ietf-radext-r… Donald Eastlake