[spring] Re: Security aspects of SRv6-based overlay services
Nick Hilliard <nick@foobar.org> Fri, 04 September 2026 15:31 UTC
Return-Path: <nick@foobar.org>
X-Original-To: spring@mail2.ietf.org
Delivered-To: spring@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id DAA10135972C5; Fri, 4 Sep 2026 08:31:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788535893; bh=thTpWDgfbht3FHsIQHvxZpaSNoDj9mGYJgeHXQddUgA=; h=Subject:To:Cc:References:From:Date:In-Reply-To; b=TZapGxe5pTRxri6/yqMOkH3OsanaX67SDIB0V1vDgpe6cyXgGtM/e42zoPOtRmFsr 1BmN5SmV7/RQyO4FxopXfGXRsSJK9xqHUEhIWIk88X7tihvm0irJT3Y0td/XNpvltH tKICmUFmdmRuEhogwhVdsk7nAuWsGmPsZuTh4N4k=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -5.824
X-Spam-Level:
X-Spam-Status: No, score=-5.824 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-1.624, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H_iroCdfSklO; Fri, 4 Sep 2026 08:31:33 -0700 (PDT)
Received: from mail.netability.ie (mail.netability.ie [IPv6:2a03:8900:0:100::5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 415BF135972B6; Fri, 4 Sep 2026 08:31:33 -0700 (PDT)
Received: from cupcake.localdomain (unknown [89.101.195.154]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.netability.ie (Postfix) with ESMTPSA id 40B979CDB4; Fri, 04 Sep 2026 16:31:25 +0100 (IST)
To: Alexander Vainshtein <Alexander.Vainshtein=40rbbn.com@dmarc.ietf.org>
References: <PH0PR03MB63006E0208CB4ED3E5D45626F6B52@PH0PR03MB6300.namprd03.prod.outlook.com>
From: Nick Hilliard <nick@foobar.org>
Message-ID: <26e40988-31da-d024-9e46-ebdddc499c4c@foobar.org>
Date: Fri, 04 Sep 2026 16:31:23 +0100
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 26.6; rv:52.0) Gecko/20100101 PostboxApp/7.0.65
MIME-Version: 1.0
In-Reply-To: <PH0PR03MB63006E0208CB4ED3E5D45626F6B52@PH0PR03MB6300.namprd03.prod.outlook.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Message-ID-Hash: UPLFRNZCSTH3N47RAOPCKNLGFTUKMX32
X-Message-ID-Hash: UPLFRNZCSTH3N47RAOPCKNLGFTUKMX32
X-MailFrom: nick@foobar.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-spring.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "draft-ietf-spring-srv6-security@ietf.org" <draft-ietf-spring-srv6-security@ietf.org>, "bess@ietf.org" <bess@ietf.org>, "spring@ietf.org" <spring@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [spring] Re: Security aspects of SRv6-based overlay services
List-Id: "Source Packet Routing in NetworkinG (SPRING)" <spring.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/spring/-sYOTGSxRmikVTuMrobYNL4S5po>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spring>
List-Help: <mailto:spring-request@ietf.org?subject=help>
List-Owner: <mailto:spring-owner@ietf.org>
List-Post: <mailto:spring@ietf.org>
List-Subscribe: <mailto:spring-join@ietf.org>
List-Unsubscribe: <mailto:spring-leave@ietf.org>
Alexander Vainshtein wrote on 04/09/2026 08:12: > E.g., a compromised Route Reflector could modify (or simply discard) the > BGP Prefix SID Attribute in routes of such families as VPN-IP or EVPN - > with a devastating effect on the services., while such an attack would > not have any impact on IP-VPN and EVPN services over MPLS underlay. > > What, if anything, do I miss? In practice, if you have a compromised RR, your entire network is fully compromised. In regard to a standards specification, a compromised RR would be out of scope for the security section. It doesn't represent a failure or security weakness specific to srv6. Nick
- [spring] Security aspects of SRv6-based overlay s… Alexander Vainshtein
- [spring] Re: [bess] Security aspects of SRv6-base… Alvaro Retana
- [spring] Re: [EXTERNAL] Re: [bess] Security aspec… Alexander Vainshtein
- [spring] Re: [EXTERNAL] Re: [bess] Security aspec… James Guichard
- [spring] Re: [EXTERNAL] Re: [bess] Security aspec… Ketan Talaulikar
- [spring] Re: Security aspects of SRv6-based overl… Nick Hilliard