Skip to main content

Last Call Review of draft-ietf-ospf-sr-yang-33
review-ietf-ospf-sr-yang-33-secdir-lc-bonnell-2025-02-06-00

Request Review of draft-ietf-ospf-sr-yang
Requested revision No specific revision (document currently at 50)
Type IETF Last Call Review
Team Security Area Directorate (secdir)
Deadline 2025-01-30
Requested 2025-01-16
Authors Yingzhen Qu , Acee Lindem , Zhaohui (Jeffrey) Zhang , Ing-Wher (Helen) Chen
I-D last updated 2025-12-09 (Latest revision 2025-05-09)
Completed reviews Rtgdir IETF Last Call review of -22 by Julien Meuric (diff)
Yangdoctors IETF Last Call review of -28 by Reshad Rahman (diff)
Yangdoctors Early review of -20 by Reshad Rahman (diff)
Opsdir IETF Last Call review of -33 by Joe Clarke (diff)
Genart IETF Last Call review of -33 by Gyan Mishra (diff)
Secdir IETF Last Call review of -33 by Corey Bonnell (diff)
Assignment Reviewer Corey Bonnell
State Completed
Request IETF Last Call review on draft-ietf-ospf-sr-yang by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/_yLMqMtbBWAbQZpi829Kb4NzGKs
Reviewed revision 33 (document currently at 50)
Result Ready
Completed 2025-02-06
review-ietf-ospf-sr-yang-33-secdir-lc-bonnell-2025-02-06-00
My primary area of experience is PKI, and this is my first foray for delving
into YANG. I hope the comments below are useful despite that.

I have reviewed the document and found that the security considerations section
provides appropriate guidance on the use of secure transport protocols as well
as access controls for reading and writing the nodes defined in this document.
Additionally, there is sufficient enumeration of the specific risks posed by
allowing an attacker write access to the nodes defined in the document or
allowing an attacker read access to nodes. Given this, I believe the current
security considerations section is sufficient.

Nit:
In the Security Considerations section, replace "Dos" with "DoS" in several
locations for consistency.

Question:
Should the various read-only nodes defined in this document (such as
"prefix-sid-sub-tlvs") be marked as "config false" as they are not writable?