Skip to main content

IETF Last Call Review of draft-ietf-opsawg-discardmodel-13
review-ietf-opsawg-discardmodel-13-secdir-lc-piper-2026-06-09-00

Request Review of draft-ietf-opsawg-discardmodel
Requested revision No specific revision (document currently at 14)
Type IETF Last Call Review
Team Security Area Directorate (secdir)
Deadline 2026-06-22
Requested 2026-06-08
Authors John Evans , Oleksandr Pylypenko , Jeffrey Haas , Aviran Kadosh , Mohamed Boucadair
I-D last updated 2026-07-09 (Latest revision 2026-06-24)
Completed reviews Yangdoctors Early review of -03 by Ladislav Lhotka (diff)
Opsdir Early review of -09 by Sergio Belotti (diff)
Intdir Early review of -09 by Satoru Matsushima (diff)
Yangdoctors Early review of -10 by Ladislav Lhotka (diff)
Secdir IETF Last Call review of -13 by Derrell Piper (diff)
Tsvart IETF Last Call review of -13 by Michael Tüxen (diff)
Genart IETF Last Call review of -13 by Roni Even (diff)
Intdir Telechat review of -14 by Carlos Pignataro
Assignment Reviewer Derrell Piper
State Completed
Request IETF Last Call review on draft-ietf-opsawg-discardmodel by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/krjO3LLqXklGMs-8jprR3iinlBE
Reviewed revision 13 (document currently at 14)
Result Ready
Completed 2026-06-09
review-ietf-opsawg-discardmodel-13-secdir-lc-piper-2026-06-09-00
I reviewed draft-ietf-opsawg-discardmodel-13. It defines an information
model and YANG data model for packet discard reporting.

I found no blocking security issues. The Security Considerations
adequately cover the relevant management-plane concerns, including
secure transport, mutual authentication, NACM-based access control, and
the sensitivity of readable discard counters.

One non-blocking comment: Section 8.2 identifies the per-interface
pdr:traffic and pdr:discards subtrees under if:statistics as sensitive
readable data. However, nacm:default-deny-all is applied only to the new
control-plane and device discard-stats containers, not to the interface
augment into if:statistics. The authors should either reconcile that
access-control posture or note why the per-interface breakdown is
intentionally left to deployment-specific NACM policy rather than being
marked by the module for default-deny-all protection.

Ready.