Skip to main content

IETF Last Call Review of draft-ietf-6man-snac-router-ra-flag-06
review-ietf-6man-snac-router-ra-flag-06-secdir-lc-jain-2026-05-24-00

Request Review of draft-ietf-6man-snac-router-ra-flag
Requested revision No specific revision (document currently at 08)
Type IETF Last Call Review
Team Security Area Directorate (secdir)
Deadline 2026-05-18
Requested 2026-05-04
Authors Jonathan Hui
I-D last updated 2026-06-10 (Latest revision 2026-06-05)
Completed reviews Genart IETF Last Call review of -02 by Gyan Mishra (diff)
Secdir IETF Last Call review of -02 by Shivan Kaul Sahib (diff)
Opsdir IETF Last Call review of -02 by Adrian Farrel (diff)
Iotdir Telechat review of -02 by Thomas Fossati (diff)
Intdir Telechat review of -02 by Juan-Carlos Zúñiga (diff)
Genart IETF Last Call review of -06 by Gyan Mishra (diff)
Secdir IETF Last Call review of -06 by Prachi Jain (diff)
Assignment Reviewer Prachi Jain
State Completed
Request IETF Last Call review on draft-ietf-6man-snac-router-ra-flag by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/FXUfx00KXejhWZB0HMRBfbqTJZ8
Reviewed revision 06 (document currently at 08)
Result Has issues
Completed 2026-05-24
review-ietf-6man-snac-router-ra-flag-06-secdir-lc-jain-2026-05-24-00
Sorry for the delay.

I have not identified any new security issues. However, I want to note that
several concerns raised against earlier versions remain unaddressed in v06 as
well. Also it looks like that v06 has regressed. The cross-reference to
snac-simple's security considerations was deleted. Section 6 now provides less
guidance than earlier.

These 2 issues are still unaddressed:

* An on-link attacker can forge the SNAC flag and affect SNAC router behavior.
RFC 4861's Hop Limit=255 only protects against off-link attackers. * An on-path
attacker can strip the SNAC flag from a legitimate RA before forwarding it,
causing receiving devices to fall back to degraded behavior silently.

If I am missing some conversation here, please let me know but I would like to
ensure that we clarify this before moving forward.