[secdir] secdir review of draft-ietf-mpls-lsp-ping-enhanced-dsmap-10

Joe Salowey <jsalowey@cisco.com> Tue, 02 August 2011 17:25 UTC

Return-Path: <jsalowey@cisco.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 94FB411E807F; Tue, 2 Aug 2011 10:25:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -105.099
X-Spam-Level:
X-Spam-Status: No, score=-105.099 tagged_above=-999 required=5 tests=[AWL=-2.500, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PUFAyJnOPcsJ; Tue, 2 Aug 2011 10:25:58 -0700 (PDT)
Received: from rcdn-iport-5.cisco.com (rcdn-iport-5.cisco.com [173.37.86.76]) by ietfa.amsl.com (Postfix) with ESMTP id DDEFE11E807B; Tue, 2 Aug 2011 10:25:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=jsalowey@cisco.com; l=830; q=dns/txt; s=iport; t=1312305968; x=1313515568; h=from:content-transfer-encoding:subject:date:message-id: to:mime-version; bh=/wuhDS+q0Pjfif7BxO55hh0Z4HycIMVcnxPOZ0KOOng=; b=HS8cCBLPWOCoRbrTS1+lRwVa2wZHsukD+jkW/8PGefocSc/DQR7WXqd6 8nFFAG7hwfp9WIVn2rXLD/jmZh7wj7aeH42GHBzxQon/nWiF+St+3Dd/O WVqOh4aipHv6Vl2uVZ9n2BemjR7/bhhuTChm3xKj4nVPdvSQznk6px++n 0=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AvwEAGsyOE6rRDoJ/2dsb2JhbABCp2V3gVkBJ4F9ATSoaQGedIVjXwSHWoshhQeLfQ
X-IronPort-AV: E=Sophos;i="4.67,307,1309737600"; d="scan'208";a="8886544"
Received: from mtv-core-4.cisco.com ([171.68.58.9]) by rcdn-iport-5.cisco.com with ESMTP; 02 Aug 2011 17:26:07 +0000
Received: from [10.33.249.202] ([10.33.249.202]) by mtv-core-4.cisco.com (8.14.3/8.14.3) with ESMTP id p72HQ6uv030845; Tue, 2 Aug 2011 17:26:06 GMT
From: Joe Salowey <jsalowey@cisco.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Date: Tue, 02 Aug 2011 10:26:02 -0700
Message-Id: <6B1C78CB-B687-45B1-BA74-1B02FDFCB86D@cisco.com>
To: secdir@ietf.org, The IESG <iesg@ietf.org>, draft-ietf-mpls-lsp-ping-enhanced-dsmap.all@tools.ietf.org
Mime-Version: 1.0 (Apple Message framework v1084)
X-Mailer: Apple Mail (2.1084)
Subject: [secdir] secdir review of draft-ietf-mpls-lsp-ping-enhanced-dsmap-10
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Aug 2011 17:25:58 -0000

I have reviewed this document as part of the security directorate's 
ongoing effort to review all IETF documents being processed by the 
IESG.  These comments were written primarily for the benefit of the 
security area directors.  Document editors and WG chairs should treat 
these comments just like any other last call comments.

This document describes modifications to LSP Ping to allow it to work with MPLS tunnels.  It is possible that in some cases a provider may not want to disclose information about tunnels.  The security considerations in the document describe mechanisms to keep this information private.   In addition the security considerations reference RFC 4379 which seems sufficient.  

One nit: the first sentence in section 1 is missing a closing parenthesis. 

Joe