[spring] Re: Second WG Last Call: draft-ietf-spring-srv6-s ecurity-14 (Ends 2026-06-02)

Nick Buraglio <[email protected]> Sat, 30 May 2026 10:08:53 -0500
Newsgroups gmane.ietf.spring,gmane.ietf.ipv6
Message-ID <CACMsEX-trTCRh8Y1X7qX33mNW-rO6KPU7kj099-i41xuvui1pA@mail.gmail.com>
--===============3147002658211938018==
Content-Type: multipart/alternative; boundary="000000000000995f4906530a57dd"

--000000000000995f4906530a57dd
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Fri, May 29, 2026 at 9:42=E2=80=AFPM Suresh Krishnan <suresh.krishnan@gm=
ail.com>
wrote:

> Hi chairs/authors,
>   Thank you for your hard work on this important document. I have reviewe=
d
> draft-ietf-spring-srv6-security-14 and I think it is ready to progress
> further in the IETF process. I do have some minor comments that you may
> want to address
>
> * Section 6.1.
>
> This sentence is missing a verb and does not read right. Suggest rewordin=
g
> to
>
> OLD:
> While it is possible for packet manipulation and processing attacks
> against all the fields of the IPv6 header and its extension headers, this
> document limits itself to the IPv6 header and the SRH.
>
> NEW:
> While packet manipulation and processing attacks are possible against all
> the fields of the IPv6 header and its extension headers, this document
> limits itself to attacks on the IPv6 header and the SRH.
>
> Agreed, fixed.


> * Section 6.2.1.1.
>
> This sentence is a bit confusing. Suggest rewording
>
> OLD:
> However, it facilitates more complex on-path attacks by redirecting
> traffic to another node that the attacker has access to with more
> processing resources.
>
> NEW:
> However, it facilitates more complex on-path attacks by redirecting
> traffic to another node, with more processing resources, that the attacke=
r
> has access to.
>
> * Section 8.1.
>
> Not sure what "take care of=E2=80=9D means here? I would suggest using =
=E2=80=9Chandle=E2=80=9D or
> =E2=80=9Cinspect=E2=80=9D depending on what you intend to say here.
>

Good catch, changed to:

NEW:
The security devices operating in SRv6 enabled networks need to understand
and have the capability to process SRv6 packets.

>
> Regards
> Suresh
>
> > On May 18, 2026, at 3:44=E2=80=AFPM, Alvaro Retana via Datatracker <
> [email protected]> wrote:
> >
> > This message starts a Second WG Last Call for:
> > draft-ietf-spring-srv6-security-14
> >
> > This Working Group Last Call ends on 2026-06-02
> >
> > Abstract:
> >   SRv6 is a traffic engineering, encapsulation and steering mechanism
> >   utilizing IPv6 addresses to identify segments in a pre-defined
> >   policy.  This document discusses security considerations in SRv6
> >   networks, including the potential threats and the possible mitigation
> >   methods.  The document does not define any new security protocols or
> >   extensions to existing protocols.
> >
> > File can be retrieved from:
> >
> > Please review and indicate your support or objection to proceed with th=
e
> > publication of this document by replying to this email keeping
> > [email protected] in copy. Objections should be explained and suggestions
> to
> > resolve them are highly appreciated.
> >
> > Authors, and WG participants in general, are reminded of the Intellectu=
al
> > Property Rights (IPR) disclosure obligations described in BCP 79 [1].
> > Appropriate IPR disclosures required for full conformance with the
> provisions
> > of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.
> > Sanctions available for application to violators of IETF IPR Policy can
> be
> > found at [3].
> >
> > Thank you.
> >
> > [1] https://datatracker.ietf.org/doc/bcp78/
> > [2] https://datatracker.ietf.org/doc/bcp79/
> > [3] https://datatracker.ietf.org/doc/rfc6701/
> >
> > The IETF datatracker status page for this Internet-Draft is:
> > https://datatracker.ietf.org/doc/draft-ietf-spring-srv6-security/
> >
> > There is also an HTML version available at:
> > https://www.ietf.org/archive/id/draft-ietf-spring-srv6-security-14.html
> >
> > A diff from the previous version is available at:
> >
> https://author-tools.ietf.org/iddiff?url2=3Ddraft-ietf-spring-srv6-securi=
ty-14
> >
> > _______________________________________________
> > spring mailing list -- [email protected]
> > To unsubscribe send an email to [email protected]
>
>

--000000000000995f4906530a57dd
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g=
mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, May 29,=
 2026 at 9:42=E2=80=AFPM Suresh Krishnan &lt;<a href=3D"mailto:suresh.krish=
[email protected]">[email protected]</a>&gt; wrote:<br></div><blockquot=
e class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px s=
olid rgb(204,204,204);padding-left:1ex">Hi chairs/authors,<br>
=C2=A0 Thank you for your hard work on this important document. I have revi=
ewed draft-ietf-spring-srv6-security-14 and I think it is ready to progress=
 further in the IETF process. I do have some minor comments that you may wa=
nt to address<br>
<br>
* Section 6.1.<br>
<br>
This sentence is missing a verb and does not read right. Suggest rewording =
to<br>
<br>
OLD:<br>
While it is possible for packet manipulation and processing attacks against=
 all the fields of the IPv6 header and its extension headers, this document=
 limits itself to the IPv6 header and the SRH.<br>
<br>
NEW:<br>
While packet manipulation and processing attacks are possible against all t=
he fields of the IPv6 header and its extension headers, this document limit=
s itself to attacks on the IPv6 header and the SRH.<br>
<br></blockquote><div>Agreed, fixed.=C2=A0</div><div>=C2=A0</div><blockquot=
e class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px s=
olid rgb(204,204,204);padding-left:1ex">
* Section 6.2.1.1.<br>
<br>
This sentence is a bit confusing. Suggest rewording <br>
<br>
OLD:<br>
However, it facilitates more complex on-path attacks by redirecting traffic=
 to another node that the attacker has access to with more processing resou=
rces.<br>
<br>
NEW:<br>
However, it facilitates more complex on-path attacks by redirecting traffic=
 to another node, with more processing resources, that the attacker has acc=
ess to.<br>
<br>
* Section 8.1.<br>
<br>
Not sure what &quot;take care of=E2=80=9D means here? I would suggest using=
 =E2=80=9Chandle=E2=80=9D or =E2=80=9Cinspect=E2=80=9D depending on what yo=
u intend to say here.<br></blockquote><div><br></div><div>Good catch, chang=
ed to:=C2=A0</div><div><br></div><div>NEW:=C2=A0</div><div><font face=3D"ar=
ial, sans-serif" style=3D"background-color:rgb(255,255,255)" color=3D"#0000=
00"><span style=3D"white-space:pre">The security devices operating in SRv6 =
enabled networks need to understand and have the capability to process SRv6=
 packets.</span>=C2=A0</font></div><blockquote class=3D"gmail_quote" style=
=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding=
-left:1ex">
<br>
Regards<br>
Suresh<br>
<br>
&gt; On May 18, 2026, at 3:44=E2=80=AFPM, Alvaro Retana via Datatracker &lt=
;<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>=
&gt; wrote:<br>
&gt; <br>
&gt; This message starts a Second WG Last Call for:<br>
&gt; draft-ietf-spring-srv6-security-14<br>
&gt; <br>
&gt; This Working Group Last Call ends on 2026-06-02<br>
&gt; <br>
&gt; Abstract:<br>
&gt;=C2=A0 =C2=A0SRv6 is a traffic engineering, encapsulation and steering =
mechanism<br>
&gt;=C2=A0 =C2=A0utilizing IPv6 addresses to identify segments in a pre-def=
ined<br>
&gt;=C2=A0 =C2=A0policy.=C2=A0 This document discusses security considerati=
ons in SRv6<br>
&gt;=C2=A0 =C2=A0networks, including the potential threats and the possible=
 mitigation<br>
&gt;=C2=A0 =C2=A0methods.=C2=A0 The document does not define any new securi=
ty protocols or<br>
&gt;=C2=A0 =C2=A0extensions to existing protocols.<br>
&gt; <br>
&gt; File can be retrieved from:<br>
&gt; <br>
&gt; Please review and indicate your support or objection to proceed with t=
he<br>
&gt; publication of this document by replying to this email keeping<br>
&gt; <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</=
a> in copy. Objections should be explained and suggestions to<br>
&gt; resolve them are highly appreciated.<br>
&gt; <br>
&gt; Authors, and WG participants in general, are reminded of the Intellect=
ual<br>
&gt; Property Rights (IPR) disclosure obligations described in BCP 79 [1].<=
br>
&gt; Appropriate IPR disclosures required for full conformance with the pro=
visions<br>
&gt; of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.<b=
r>
&gt; Sanctions available for application to violators of IETF IPR Policy ca=
n be<br>
&gt; found at [3].<br>
&gt; <br>
&gt; Thank you.<br>
&gt; <br>
&gt; [1] <a href=3D"https://datatracker.ietf.org/doc/bcp78/" rel=3D"norefer=
rer" target=3D"_blank">https://datatracker.ietf.org/doc/bcp78/</a><br>
&gt; [2] <a href=3D"https://datatracker.ietf.org/doc/bcp79/" rel=3D"norefer=
rer" target=3D"_blank">https://datatracker.ietf.org/doc/bcp79/</a><br>
&gt; [3] <a href=3D"https://datatracker.ietf.org/doc/rfc6701/" rel=3D"noref=
errer" target=3D"_blank">https://datatracker.ietf.org/doc/rfc6701/</a><br>
&gt; <br>
&gt; The IETF datatracker status page for this Internet-Draft is:<br>
&gt; <a href=3D"https://datatracker.ietf.org/doc/draft-ietf-spring-srv6-sec=
urity/" rel=3D"noreferrer" target=3D"_blank">https://datatracker.ietf.org/d=
oc/draft-ietf-spring-srv6-security/</a><br>
&gt; <br>
&gt; There is also an HTML version available at:<br>
&gt; <a href=3D"https://www.ietf.org/archive/id/draft-ietf-spring-srv6-secu=
rity-14.html" rel=3D"noreferrer" target=3D"_blank">https://www.ietf.org/arc=
hive/id/draft-ietf-spring-srv6-security-14.html</a><br>
&gt; <br>
&gt; A diff from the previous version is available at:<br>
&gt; <a href=3D"https://author-tools.ietf.org/iddiff?url2=3Ddraft-ietf-spri=
ng-srv6-security-14" rel=3D"noreferrer" target=3D"_blank">https://author-to=
ols.ietf.org/iddiff?url2=3Ddraft-ietf-spring-srv6-security-14</a><br>
&gt; <br>
&gt; _______________________________________________<br>
&gt; spring mailing list -- <a href=3D"mailto:[email protected]" target=3D"_b=
lank">[email protected]</a><br>
&gt; To unsubscribe send an email to <a href=3D"mailto:[email protected]=
g" target=3D"_blank">[email protected]</a><br>
<br>
</blockquote></div></div>

--000000000000995f4906530a57dd--


--===============3147002658211938018==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc3ByaW5nIG1h
aWxpbmcgbGlzdCAtLSBzcHJpbmdAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFp
bCB0byBzcHJpbmctbGVhdmVAaWV0Zi5vcmcK

--===============3147002658211938018==--