Skip to main content

IETF Last Call Review of draft-ietf-netmod-intf-ext-yang-19
review-ietf-netmod-intf-ext-yang-19-secdir-lc-santesson-2026-07-22-00

Request Review of draft-ietf-netmod-intf-ext-yang
Requested revision No specific revision (document currently at 19)
Type IETF Last Call Review
Team Security Area Directorate (secdir)
Deadline 2025-10-14
Requested 2025-09-30
Authors Robert Wilton , Scott Mansfield
I-D last updated 2026-06-19 (Latest revision 2026-06-19)
Completed reviews Yangdoctors Early review of -04 by Andy Bierman (diff)
Yangdoctors Early review of -16 by Andy Bierman (diff)
Intdir IETF Last Call review of -17 by Satoru Matsushima (diff)
Opsdir IETF Last Call review of -17 by Sheng Jiang (diff)
Tsvart IETF Last Call review of -17 by Michael Scharf (diff)
Secdir IETF Last Call review of -19 by Stefan Santesson
Genart IETF Last Call review of -17 by Reese Enghardt (diff)
Assignment Reviewer Stefan Santesson
State Completed
Request IETF Last Call review on draft-ietf-netmod-intf-ext-yang by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/SBObULyKa4aW91EjQ22WnoOWuvU
Reviewed revision 19
Result Ready
Completed 2026-07-22
review-ietf-netmod-intf-ext-yang-19-secdir-lc-santesson-2026-07-22-00
I have reviewed this draft and the document seems fine.

The general warning on writable nodes in the security considerations section
seems fine, but I have a question whether some of the nodes should be listed as
having "particular sensitivities/vulnerabilities."

I'm thinking in particular of the "loopback" and "mac-address" nodes.
"loopback" as it may be used to black-hole an entire physical interface, and
"mac-address" because if not protected, it could be used to set a forged MAC to
intercept traffic or bypass MAC-based access controls.

None of this should be understood as claims of problems, but just as questions
for consideration.