Skip to main content

IETF Last Call Review of draft-ietf-ippm-asymmetrical-pkts-11
review-ietf-ippm-asymmetrical-pkts-11-secdir-lc-farrell-2026-03-05-00

Request Review of draft-ietf-ippm-asymmetrical-pkts
Requested revision No specific revision (document currently at 14)
Type IETF Last Call Review
Team Security Area Directorate (secdir)
Deadline 2026-02-18
Requested 2026-02-04
Authors Greg Mirsky , Ernesto Ruffini , Henrik Nydell , Richard "Footer" Foote , Will Hawkins
I-D last updated 2026-09-03 (Latest revision 2026-03-16)
Completed reviews Tsvart Early review of -07 by Lars Eggert (diff)
Secdir IETF Last Call review of -11 by Stephen Farrell (diff)
Genart IETF Last Call review of -10 by Christer Holmberg (diff)
Assignment Reviewer Stephen Farrell
State Completed
Request IETF Last Call review on draft-ietf-ippm-asymmetrical-pkts by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/2BHcXf5aqB52EJjwjCpHpUmun_c
Reviewed revision 11 (document currently at 14)
Result Ready
Completed 2026-03-05
review-ietf-ippm-asymmetrical-pkts-11-secdir-lc-farrell-2026-03-05-00
Apologies for the late review.

The obvious potential DoS vector is well covered here and the countermeasures
seem OK given the way ippm stuff is seemingly deoployed. It might still be nice
to add some a sentence cautioning that deploying an "open" reflector on the
public Internet is likely a bad plan.

I also wondered if a heartbleed-like problem could occur, but it sems like the
extra padding TLV spec in RFC8972 covers that already.