Last Call Review of draft-ietf-detnet-ip-over-mpls-07
review-ietf-detnet-ip-over-mpls-07-secdir-lc-roca-2020-09-07-00
| Request | Review of | draft-ietf-detnet-ip-over-mpls |
|---|---|---|
| Requested revision | No specific revision (document currently at 09) | |
| Type | IETF Last Call Review | |
| Team | Security Area Directorate (secdir) | |
| Deadline | 2020-04-23 | |
| Requested | 2020-04-09 | |
| Authors | Balazs Varga , Lou Berger , Don Fedyk , Stewart Bryant , Jouni Korhonen | |
| I-D last updated | 2021-10-04 (Latest revision 2020-10-11) | |
| Completed reviews |
Rtgdir IETF Last Call review of -04
by Tomonori Takeda
(diff)
Genart IETF Last Call review of -05 by Tim Evens (diff) Secdir IETF Last Call review of -07 by Vincent Roca (diff) Tsvart IETF Last Call review of -05 by Brian Trammell (diff) |
|
| Assignment | Reviewer | Vincent Roca |
| State | Completed | |
| Request | IETF Last Call review on draft-ietf-detnet-ip-over-mpls by Security Area Directorate Assigned | |
| Posted at | https://mailarchive.ietf.org/arch/msg/secdir/R2xqUDWqbqy4-aINpT0OURrB_Ts | |
| Reviewed revision | 07 (document currently at 09) | |
| Result | Has nits | |
| Completed | 2020-09-07 |
review-ietf-detnet-ip-over-mpls-07-secdir-lc-roca-2020-09-07-00
Hello, I have reviewed this document as part of the security directorate’s ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. Summary: Has Nits I have no major concern. However I think that the Security considerations section could and should better leverage on [I-D.ietf-detnet-security] (currently it is mainly cited but that's all). Indeed, the [I-D.ietf-detnet-security] document is all about DetNet security, it introduces the problem in a clear manner, then it discusses with much detail both security risks and mitigation technics, providing high level synthesis tables, and sections 9.1 and 9.2 are even dedicated to IP and MPLS DetNet security. This is a MUST read document that provides valuable discussion (perhaps more than in the present document, sorry). I also think the [I-D.ietf-detnet-security] reference (""Deterministic Networking (DetNet) Security Considerations") should be a Normative Reference (it's currently in the Informative Reference list). Minor comments: - Section 4.1 uses the S-PE acronym when refering to the Relay Node, whereas S-PE is not expended in the Abbreviations list of section 2.2. Regards, Vincent