Re: [secdir] secdir review of draft-ietf-mpls-ipv6-only-gap-02

"Carlos Pignataro (cpignata)" <cpignata@cisco.com> Tue, 28 October 2014 17:50 UTC

Return-Path: <cpignata@cisco.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B00E1A90FF; Tue, 28 Oct 2014 10:50:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.511
X-Spam-Level:
X-Spam-Status: No, score=-14.511 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xvIdF_hnOY0w; Tue, 28 Oct 2014 10:50:29 -0700 (PDT)
Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 296601A90F3; Tue, 28 Oct 2014 10:49:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2202; q=dns/txt; s=iport; t=1414518549; x=1415728149; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=QPUCqTN981BWBb/8O5x+Sd0pcY9BlzNgM8hbUEvd1aE=; b=aPtxYVBHGsyivf4VogY1YujEDoY46ckrZ7r2Xupt3wZ2qRw2Sl8+85Nk Tg4exQcYvaWRr2Og4SyasAS++NbxyS0G3s+JmZrp2IBt6IP/cE00680gU omFeAr5ubrX12RLCj+cyfIaXuHoAfdYqOuvh2+bhcrpvDOb4t4YiFsUXk 8=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhUFAJ3WT1StJA2J/2dsb2JhbABcgmsjgSwE1gsCgR0WAQEBAQF9hAIBAQEDAXkFCwIBCBguMiUCBA4FiDgJAch/AQEBAQEBAQEBAQEBAQEBAQEBARmQVjMHgy2BHgEEj22CHocNhFCBMYNJjTuEAYN4bIFIgQMBAQE
X-IronPort-AV: E=Sophos;i="5.04,804,1406592000"; d="scan'208";a="367217273"
Received: from alln-core-4.cisco.com ([173.36.13.137]) by rcdn-iport-3.cisco.com with ESMTP; 28 Oct 2014 17:49:08 +0000
Received: from xhc-aln-x11.cisco.com (xhc-aln-x11.cisco.com [173.36.12.85]) by alln-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id s9SHn8BM008403 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Tue, 28 Oct 2014 17:49:08 GMT
Received: from xmb-aln-x02.cisco.com ([fe80::8c1c:7b85:56de:ffd1]) by xhc-aln-x11.cisco.com ([173.36.12.85]) with mapi id 14.03.0195.001; Tue, 28 Oct 2014 12:49:08 -0500
From: "Carlos Pignataro (cpignata)" <cpignata@cisco.com>
To: Tobias Gondrom <tobias.gondrom@gondrom.org>
Thread-Topic: secdir review of draft-ietf-mpls-ipv6-only-gap-02
Thread-Index: AQHP8td4tLW89gRha0aSOHC69VI04w==
Date: Tue, 28 Oct 2014 17:49:07 +0000
Message-ID: <4BAF9B31-0AEE-45F9-93EB-244ED28C119B@cisco.com>
References: <53E00686.7030909@gondrom.org> <54482C9B.6070703@gondrom.org>
In-Reply-To: <54482C9B.6070703@gondrom.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.150.172.248]
Content-Type: text/plain; charset="Windows-1252"
Content-ID: <1B1CF8A62799C048A114B255CC1E20AE@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/secdir/wIIOomrs71qrziXiDLPv09hFwvM
Cc: "draft-ietf-mpls-ipv6-only-gap.all@tools.ietf.org" <draft-ietf-mpls-ipv6-only-gap.all@tools.ietf.org>, "iesg@ietf.org" <iesg@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>
Subject: Re: [secdir] secdir review of draft-ietf-mpls-ipv6-only-gap-02
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Oct 2014 17:50:32 -0000

Tobias,

Many thanks for your review, and apologies for a delayed response. Please see inline.

> On Oct 22, 2014, at 6:15 PM, Tobias Gondrom <tobias.gondrom@gondrom.org> wrote:
> 
> 
> I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG.  These comments were written primarily for the benefit of the security area directors.  Document editors and WG chairs should treat these comments just like any other last call comments.
> 
> 
> The draft is informational and identifies and analyses gaps that must be addressed in order to allow MPLS-related protocols and applications to be used with IPv6-only networks.
> 
> The document appears ready for publication.

Thanks!

> 
> The security considerations section (section 8) only states that changing the address family used for MPLS network operation does not fundamentally alter the security considerations of the existing protocol. Which is basically correct. It could have been interesting to look at the gaps analysis from a security perspective and see which of the MPLS IPv6-only gaps has security implications that need to be addressed. I.e. which gaps are security related. However, that is not essential.
> 

Ack.

> Comment:
> 1. Abstract and Section 1:
> the sentence "This document is not intended to highlight a particular vendor's implementation (or lack thereof)" sounds odd. Is there a WG discussion background or why is this document speaking of one "particular vendor's implementation”?

We just wanted to proactively clarify that this gap analysis is one on specifications and not in implementations. The important part of that sentence is what follows: “, but rather to focus on gaps in the standards defining the MPLS suite."

> 

> Nits:
> - section 3.3.1.1. EVPN
> formating: do you want to add one line at the end of the section: "Gap: Minor….
> “
> 

Good catch — fixed.


> I did not find anything else in my review.
> 
> 


Thanks!

Carlos.

> Thank you and best regards.
> 
> Tobias
>