IETF Last Call Review of draft-ietf-opsawg-discardmodel-13
review-ietf-opsawg-discardmodel-13-secdir-lc-piper-2026-06-09-00
review-ietf-opsawg-discardmodel-13-secdir-lc-piper-2026-06-09-00
I reviewed draft-ietf-opsawg-discardmodel-13. It defines an information model and YANG data model for packet discard reporting. I found no blocking security issues. The Security Considerations adequately cover the relevant management-plane concerns, including secure transport, mutual authentication, NACM-based access control, and the sensitivity of readable discard counters. One non-blocking comment: Section 8.2 identifies the per-interface pdr:traffic and pdr:discards subtrees under if:statistics as sensitive readable data. However, nacm:default-deny-all is applied only to the new control-plane and device discard-stats containers, not to the interface augment into if:statistics. The authors should either reconcile that access-control posture or note why the per-interface breakdown is intentionally left to deployment-specific NACM policy rather than being marked by the module for default-deny-all protection. Ready.