Skip to main content

IETF Last Call Review of draft-ietf-pce-multipath-25
review-ietf-pce-multipath-25-secdir-lc-mandelberg-2026-05-27-00

Request Review of draft-ietf-pce-multipath
Requested revision No specific revision (document currently at 29)
Type IETF Last Call Review
Team Security Area Directorate (secdir)
Deadline 2026-06-03
Requested 2026-05-20
Authors Mike Koldychev , Samuel Sidor
I-D last updated 2026-08-24 (Latest revision 2026-06-23)
Completed reviews Opsdir Early review of -19 by Italo Busi (diff)
Rtgdir Early review of -18 by Cheng Li (diff)
Genart IETF Last Call review of -25 by Stewart Bryant (diff)
Secdir IETF Last Call review of -25 by David Mandelberg (diff)
Tsvart IETF Last Call review of -27 by Vidhi Goel (diff)
Assignment Reviewer David Mandelberg
State Completed
Request IETF Last Call review on draft-ietf-pce-multipath by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/HFC9yy6az2avMqox3DGTUR-Lsmc
Reviewed revision 25 (document currently at 29)
Result Has nits
Completed 2026-05-27
review-ietf-pce-multipath-25-secdir-lc-mandelberg-2026-05-27-00
(nit) Could zero weights in the MULTIPATH-WEIGHT TLV trigger a denial of
service from dividing by zero? Would it make sense to require Weight to be
non-zero?

(nit) Section 3.4 says "If no opposite-direction path exists, then this field
MUST be set to 0, a value reserved to indicate the absence of a Path ID." What
should an implementation do if it receives a PATH-ATTRIB with multiple
MULTIPATH-OPPDIR-PATH TLVs, some of which have zero Opposite Direction Path ID
and some have non-zero Opposite Direction Path ID? If one implementation treats
that as no opposite path (ignoring the non-zeroes) and another implementation
ignores the zeroes, could that be a security issue?

Otherwise, looks good.