[Tsvwg] IETF LC comments on draft-ietf-tsvwg-rsvp-ipsec

Magnus Westerlund <magnus.westerlund@ericsson.com> Fri, 13 October 2006 09:55 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1GYJl8-0006Gs-HT; Fri, 13 Oct 2006 05:55:18 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1GYJl7-0006Gn-Ij for tsvwg@ietf.org; Fri, 13 Oct 2006 05:55:17 -0400
Received: from mailgw3.ericsson.se ([193.180.251.60]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1GYJl0-0002ag-Vt for tsvwg@ietf.org; Fri, 13 Oct 2006 05:55:17 -0400
Received: from esealmw129.eemea.ericsson.se (unknown [153.88.254.120]) by mailgw3.ericsson.se (Symantec Mail Security) with ESMTP id 59C7154C; Fri, 13 Oct 2006 11:55:10 +0200 (CEST)
Received: from esealmw127.eemea.ericsson.se ([153.88.254.171]) by esealmw129.eemea.ericsson.se with Microsoft SMTPSVC(6.0.3790.1830); Fri, 13 Oct 2006 11:55:09 +0200
Received: from [147.214.30.247] ([147.214.30.247]) by esealmw127.eemea.ericsson.se with Microsoft SMTPSVC(6.0.3790.1830); Fri, 13 Oct 2006 11:55:09 +0200
Message-ID: <452F627D.9040202@ericsson.com>
Date: Fri, 13 Oct 2006 11:55:09 +0200
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
User-Agent: Thunderbird 1.5.0.7 (Windows/20060909)
MIME-Version: 1.0
To: "Francois Le Faucheur (flefauch)" <flefauch@cisco.com>, Bruce Davie <bdavie@cisco.com>, "Bose, Pratik" <pratik.bose@lmco.com>, Christou Chris <christou_chris@bah.com>, davenport_michael@bah.com, tsvwg <tsvwg@ietf.org>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 7bit
X-OriginalArrivalTime: 13 Oct 2006 09:55:09.0546 (UTC) FILETIME=[AB304CA0:01C6EEAD]
X-Brightmail-Tracker: AAAAAA==
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 39bd8f8cbb76cae18b7e23f7cf6b2b9f
Cc:
Subject: [Tsvwg] IETF LC comments on draft-ietf-tsvwg-rsvp-ipsec
X-BeenThere: tsvwg@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Transport Area Working Group <tsvwg.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/tsvwg>, <mailto:tsvwg-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:tsvwg@ietf.org>
List-Help: <mailto:tsvwg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/tsvwg>, <mailto:tsvwg-request@ietf.org?subject=subscribe>
Errors-To: tsvwg-bounces@ietf.org

Hi, the IESG received the below comment during the ongoing IETF LC. I 
would appreciate some response to it.

"I think that the "Security Considerations" section of this
document is significantly thin.  There are significant security risks
associated with this sort of aggregation that I don't see discussed
in much detail.  There should also be at least some mention of traffic
analysis issues and the potential DDOS attacks on the network
operator arising from this usage.

Unlike RIPv2 Authentication, RSVP Authentication has never had
any measurably large deployment, as near as I can tell.  A practical
to deploy key management strategy is not apparent to me right now
for RSVP Authentication.  RSVP Auth keys need to be placed in all
of the devices along a dynamic and *changing* flow path, so it is
much harder to pre-position manual keys along the whole path.
By contrast, OSPF and RIP have a well-defined and static set of
legitimate participating routers, so one can pre-position manual keys
in all of those OSPF/RIP routers (and that has been commonly done
in numerous enterprise networks using OSPFv2 Auth or RIPv2 Auth).

If this gets published without addressing the above issues,
I think EXPERIMENTAL would be more appropriate than STANDARDS-TRACK.
That would let the community of interest have a stable spec
to reference, as they sort through the poortly addressed issues
that are outlined above."


Best Regards

Magnus Westerlund

Multimedia Technologies, Ericsson Research EAB/TVA/A
----------------------------------------------------------------------
Ericsson AB                | Phone +46 8 4048287
Torshamsgatan 23           | Fax   +46 8 7575550
S-164 80 Stockholm, Sweden | mailto: magnus.westerlund@ericsson.com