Liaison statement
Response re: draft Technical Report XSTR.srsec and coordination with IETF SPRING WG
Additional information about IETF liaison relationships is available on the
IETF webpage
and the
Internet Architecture Board liaison webpage.
| State | Posted |
|---|---|
| Submitted Date | 2026-08-04 |
| From Group | spring |
| From Contact | Scott Mansfield <Scott.Mansfield@Ericsson.com> |
| To Group | ITU-T-SG-17 |
| To Contacts | tsbsg17@itu.int arnaud.taddei.sdo@gmail.com hroh@tta.or.kr ta-isohara@kddi.com wangkeyj@chinamobile.com |
| Cc | Jim Guichard <james.n.guichard@futurewei.com> Alvaro Retana <aretana.ietf@gmail.com> Ketan Talaulikar <ketant.ietf@gmail.com> Scott Mansfield <Scott.Mansfield@Ericsson.com> Joel Halpern <jmh@joelhalpern.com> Source Packet Routing in Networking Discussion List <spring@ietf.org> Bruno Decraene <bruno.decraene@orange.com> Gunter Van de Velde <gunter.van_de_velde@nokia.com> |
| Response Contact | Bruno Decraene <bruno.decraene@orange.com> Alvaro Retana <aretana.ietf@gmail.com> Joel Halpern <jmh@joelhalpern.com> |
| Technical Contact | Alvaro Retana <aretana.ietf@gmail.com> |
| Purpose | In response |
| Attachments | (None) |
| Liaisons referred by this one |
LS on the progress and coordination on draft Technical Report ITU-T XSTR.srsec related to segment routing IPv6 (SRv6) security in ITU-T Study Group 17
|
| Body |
Dear ITU-T SG17 colleagues, Thank you for the Liaison Statement. We are glad to provide an update on the status of SRv6 security work in the IETF, as requested. As is required practice in the IETF, all documents include Security Considerations. Specifically, all SRv6-related documents, including extensions, include specific Security Considerations. Additionally, the SPRING Working Group is developing a standalone document on the topic. "Segment Routing IPv6 Security Considerations" (draft-ietf-spring-srv6-security) is currently in Working Group Last Call in the SPRING Working Group, which is the final stage of WG review before it is submitted for IETF-wide and IESG review on the way to publication as an RFC. It represents mature, near-consensus text on this topic. draft-ietf-spring-srv6-security-16 (the current revision) addresses every SRv6-specific topic covered in XSTR.srsec — including information leakage/reconnaissance, resource abuse and SID/policy tampering, resource exhaustion, and the recommended countermeasures (HMAC-based integrity protection, trusted-domain/address filtering, encrypted control-plane channels) — generally in more depth and with more detailed threat and mitigation taxonomies. The additional risks XSTR.srsec discusses (e.g., LLDP-based topology poisoning, controller impersonation, flow-table exhaustion, network fingerprinting) are specific to particular SDN-controller/NFV deployment architectures rather than to SRv6 itself, and so fall outside the scope of an SRv6-focused analysis. Given the substantial overlap, we believe the most effective path for continued coordination is for SG17 experts to engage directly with draft-ietf-spring-srv6-security while it is still open for comment. We warmly invite SG17 to: - Review draft-ietf-spring-srv6-security-16; [1] - Raise any gaps, disagreements, or additional considerations on the SPRING Working Group mailing list (spring@ietf.org), during the Working Group Last Call or IETF Last Call periods. We believe this is the best way to ensure a single, consistent, and authoritative treatment of SRv6 security considerations that both organizations can reference going forward, and we look forward to SG17's input on the SPRING mailing list. Best regards, Alvaro Retana Chair, SPRING Working Group, IETF (on behalf of the SPRING WG chairs) [1] https://datatracker.ietf.org/doc/draft-ietf-spring-srv6-security/ |