IETF Last Call Review of draft-ietf-netmod-intf-ext-yang-19
review-ietf-netmod-intf-ext-yang-19-secdir-lc-santesson-2026-07-22-00
review-ietf-netmod-intf-ext-yang-19-secdir-lc-santesson-2026-07-22-00
I have reviewed this draft and the document seems fine. The general warning on writable nodes in the security considerations section seems fine, but I have a question whether some of the nodes should be listed as having "particular sensitivities/vulnerabilities." I'm thinking in particular of the "loopback" and "mac-address" nodes. "loopback" as it may be used to black-hole an entire physical interface, and "mac-address" because if not protected, it could be used to set a forged MAC to intercept traffic or bypass MAC-based access controls. None of this should be understood as claims of problems, but just as questions for consideration.