Skip to main content

Liaison statement
Response re: draft Technical Report XSTR.srsec and coordination with IETF SPRING WG

Additional information about IETF liaison relationships is available on the IETF webpage and the Internet Architecture Board liaison webpage.
State Posted
Submitted Date 2026-08-04
From Group spring
From Contact Scott Mansfield <Scott.Mansfield@Ericsson.com>
To Group ITU-T-SG-17
To Contacts tsbsg17@itu.int
arnaud.taddei.sdo@gmail.com
hroh@tta.or.kr
ta-isohara@kddi.com
wangkeyj@chinamobile.com
Cc Jim Guichard <james.n.guichard@futurewei.com>
Alvaro Retana <aretana.ietf@gmail.com>
Ketan Talaulikar <ketant.ietf@gmail.com>
Scott Mansfield <Scott.Mansfield@Ericsson.com>
Joel Halpern <jmh@joelhalpern.com>
Source Packet Routing in Networking Discussion List <spring@ietf.org>
Bruno Decraene <bruno.decraene@orange.com>
Gunter Van de Velde <gunter.van_de_velde@nokia.com>
Response Contact Bruno Decraene <bruno.decraene@orange.com>
Alvaro Retana <aretana.ietf@gmail.com>
Joel Halpern <jmh@joelhalpern.com>
Technical Contact Alvaro Retana <aretana.ietf@gmail.com>
Purpose In response
Attachments (None)
Liaisons referred by this one LS on the progress and coordination on draft Technical Report ITU-T XSTR.srsec related to segment routing IPv6 (SRv6) security in ITU-T Study Group 17
Body
Dear ITU-T SG17 colleagues,

Thank you for the Liaison Statement. We are glad to provide an update on the
status of SRv6 security work in the IETF, as requested.

As is required practice in the IETF, all documents include Security
Considerations. Specifically, all SRv6-related documents, including extensions,
include specific Security Considerations.

Additionally, the SPRING  Working Group is developing a standalone document on
the topic. "Segment Routing IPv6 Security Considerations"
(draft-ietf-spring-srv6-security) is currently in Working Group Last Call in
the SPRING Working Group, which is the final stage of WG review before it is
submitted for IETF-wide and IESG review on the way to publication as an RFC. It
represents mature, near-consensus text on this topic.

draft-ietf-spring-srv6-security-16 (the current revision) addresses every
SRv6-specific topic covered in XSTR.srsec — including information
leakage/reconnaissance, resource abuse and SID/policy tampering, resource
exhaustion, and the recommended countermeasures (HMAC-based integrity
protection, trusted-domain/address filtering, encrypted control-plane channels)
— generally in more depth and with more detailed threat and mitigation
taxonomies. The additional risks XSTR.srsec discusses (e.g., LLDP-based
topology poisoning, controller impersonation, flow-table exhaustion, network
fingerprinting) are specific to particular SDN-controller/NFV deployment
architectures rather than to SRv6 itself, and so fall outside the scope of an
SRv6-focused analysis.

Given the substantial overlap, we believe the most effective path for continued
coordination is for SG17 experts to engage directly with
draft-ietf-spring-srv6-security while it is still open for comment. We warmly
invite SG17 to:

  - Review draft-ietf-spring-srv6-security-16; [1]

  - Raise any gaps, disagreements, or additional considerations on the SPRING
  Working Group mailing list (spring@ietf.org), during the Working Group Last
  Call or IETF Last Call periods.

We believe this is the best way to ensure a single, consistent, and
authoritative treatment of SRv6 security considerations that both organizations
can reference going forward, and we look forward to SG17's input on the SPRING
mailing list.

Best regards,

Alvaro Retana
Chair, SPRING Working Group, IETF (on behalf of the SPRING WG chairs)

[1] https://datatracker.ietf.org/doc/draft-ietf-spring-srv6-security/