[spring] Re: Second WG Last Call: draft-ietf-spring-srv6-s ecurity-14 (Ends 2026-06-02)
Nick Buraglio <[email protected]> Sat, 30 May 2026 10:08:53 -0500
| Newsgroups | gmane.ietf.spring,gmane.ietf.ipv6 |
|---|---|
| Message-ID | <CACMsEX-trTCRh8Y1X7qX33mNW-rO6KPU7kj099-i41xuvui1pA@mail.gmail.com> |
--===============3147002658211938018== Content-Type: multipart/alternative; boundary="000000000000995f4906530a57dd" --000000000000995f4906530a57dd Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Fri, May 29, 2026 at 9:42=E2=80=AFPM Suresh Krishnan <suresh.krishnan@gm= ail.com> wrote: > Hi chairs/authors, > Thank you for your hard work on this important document. I have reviewe= d > draft-ietf-spring-srv6-security-14 and I think it is ready to progress > further in the IETF process. I do have some minor comments that you may > want to address > > * Section 6.1. > > This sentence is missing a verb and does not read right. Suggest rewordin= g > to > > OLD: > While it is possible for packet manipulation and processing attacks > against all the fields of the IPv6 header and its extension headers, this > document limits itself to the IPv6 header and the SRH. > > NEW: > While packet manipulation and processing attacks are possible against all > the fields of the IPv6 header and its extension headers, this document > limits itself to attacks on the IPv6 header and the SRH. > > Agreed, fixed. > * Section 6.2.1.1. > > This sentence is a bit confusing. Suggest rewording > > OLD: > However, it facilitates more complex on-path attacks by redirecting > traffic to another node that the attacker has access to with more > processing resources. > > NEW: > However, it facilitates more complex on-path attacks by redirecting > traffic to another node, with more processing resources, that the attacke= r > has access to. > > * Section 8.1. > > Not sure what "take care of=E2=80=9D means here? I would suggest using = =E2=80=9Chandle=E2=80=9D or > =E2=80=9Cinspect=E2=80=9D depending on what you intend to say here. > Good catch, changed to: NEW: The security devices operating in SRv6 enabled networks need to understand and have the capability to process SRv6 packets. > > Regards > Suresh > > > On May 18, 2026, at 3:44=E2=80=AFPM, Alvaro Retana via Datatracker < > [email protected]> wrote: > > > > This message starts a Second WG Last Call for: > > draft-ietf-spring-srv6-security-14 > > > > This Working Group Last Call ends on 2026-06-02 > > > > Abstract: > > SRv6 is a traffic engineering, encapsulation and steering mechanism > > utilizing IPv6 addresses to identify segments in a pre-defined > > policy. This document discusses security considerations in SRv6 > > networks, including the potential threats and the possible mitigation > > methods. The document does not define any new security protocols or > > extensions to existing protocols. > > > > File can be retrieved from: > > > > Please review and indicate your support or objection to proceed with th= e > > publication of this document by replying to this email keeping > > [email protected] in copy. Objections should be explained and suggestions > to > > resolve them are highly appreciated. > > > > Authors, and WG participants in general, are reminded of the Intellectu= al > > Property Rights (IPR) disclosure obligations described in BCP 79 [1]. > > Appropriate IPR disclosures required for full conformance with the > provisions > > of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any. > > Sanctions available for application to violators of IETF IPR Policy can > be > > found at [3]. > > > > Thank you. > > > > [1] https://datatracker.ietf.org/doc/bcp78/ > > [2] https://datatracker.ietf.org/doc/bcp79/ > > [3] https://datatracker.ietf.org/doc/rfc6701/ > > > > The IETF datatracker status page for this Internet-Draft is: > > https://datatracker.ietf.org/doc/draft-ietf-spring-srv6-security/ > > > > There is also an HTML version available at: > > https://www.ietf.org/archive/id/draft-ietf-spring-srv6-security-14.html > > > > A diff from the previous version is available at: > > > https://author-tools.ietf.org/iddiff?url2=3Ddraft-ietf-spring-srv6-securi= ty-14 > > > > _______________________________________________ > > spring mailing list -- [email protected] > > To unsubscribe send an email to [email protected] > > --000000000000995f4906530a57dd Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, May 29,= 2026 at 9:42=E2=80=AFPM Suresh Krishnan <<a href=3D"mailto:suresh.krish= [email protected]">[email protected]</a>> wrote:<br></div><blockquot= e class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px s= olid rgb(204,204,204);padding-left:1ex">Hi chairs/authors,<br> =C2=A0 Thank you for your hard work on this important document. I have revi= ewed draft-ietf-spring-srv6-security-14 and I think it is ready to progress= further in the IETF process. I do have some minor comments that you may wa= nt to address<br> <br> * Section 6.1.<br> <br> This sentence is missing a verb and does not read right. Suggest rewording = to<br> <br> OLD:<br> While it is possible for packet manipulation and processing attacks against= all the fields of the IPv6 header and its extension headers, this document= limits itself to the IPv6 header and the SRH.<br> <br> NEW:<br> While packet manipulation and processing attacks are possible against all t= he fields of the IPv6 header and its extension headers, this document limit= s itself to attacks on the IPv6 header and the SRH.<br> <br></blockquote><div>Agreed, fixed.=C2=A0</div><div>=C2=A0</div><blockquot= e class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px s= olid rgb(204,204,204);padding-left:1ex"> * Section 6.2.1.1.<br> <br> This sentence is a bit confusing. Suggest rewording <br> <br> OLD:<br> However, it facilitates more complex on-path attacks by redirecting traffic= to another node that the attacker has access to with more processing resou= rces.<br> <br> NEW:<br> However, it facilitates more complex on-path attacks by redirecting traffic= to another node, with more processing resources, that the attacker has acc= ess to.<br> <br> * Section 8.1.<br> <br> Not sure what "take care of=E2=80=9D means here? I would suggest using= =E2=80=9Chandle=E2=80=9D or =E2=80=9Cinspect=E2=80=9D depending on what yo= u intend to say here.<br></blockquote><div><br></div><div>Good catch, chang= ed to:=C2=A0</div><div><br></div><div>NEW:=C2=A0</div><div><font face=3D"ar= ial, sans-serif" style=3D"background-color:rgb(255,255,255)" color=3D"#0000= 00"><span style=3D"white-space:pre">The security devices operating in SRv6 = enabled networks need to understand and have the capability to process SRv6= packets.</span>=C2=A0</font></div><blockquote class=3D"gmail_quote" style= =3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding= -left:1ex"> <br> Regards<br> Suresh<br> <br> > On May 18, 2026, at 3:44=E2=80=AFPM, Alvaro Retana via Datatracker <= ;<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>= > wrote:<br> > <br> > This message starts a Second WG Last Call for:<br> > draft-ietf-spring-srv6-security-14<br> > <br> > This Working Group Last Call ends on 2026-06-02<br> > <br> > Abstract:<br> >=C2=A0 =C2=A0SRv6 is a traffic engineering, encapsulation and steering = mechanism<br> >=C2=A0 =C2=A0utilizing IPv6 addresses to identify segments in a pre-def= ined<br> >=C2=A0 =C2=A0policy.=C2=A0 This document discusses security considerati= ons in SRv6<br> >=C2=A0 =C2=A0networks, including the potential threats and the possible= mitigation<br> >=C2=A0 =C2=A0methods.=C2=A0 The document does not define any new securi= ty protocols or<br> >=C2=A0 =C2=A0extensions to existing protocols.<br> > <br> > File can be retrieved from:<br> > <br> > Please review and indicate your support or objection to proceed with t= he<br> > publication of this document by replying to this email keeping<br> > <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</= a> in copy. Objections should be explained and suggestions to<br> > resolve them are highly appreciated.<br> > <br> > Authors, and WG participants in general, are reminded of the Intellect= ual<br> > Property Rights (IPR) disclosure obligations described in BCP 79 [1].<= br> > Appropriate IPR disclosures required for full conformance with the pro= visions<br> > of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.<b= r> > Sanctions available for application to violators of IETF IPR Policy ca= n be<br> > found at [3].<br> > <br> > Thank you.<br> > <br> > [1] <a href=3D"https://datatracker.ietf.org/doc/bcp78/" rel=3D"norefer= rer" target=3D"_blank">https://datatracker.ietf.org/doc/bcp78/</a><br> > [2] <a href=3D"https://datatracker.ietf.org/doc/bcp79/" rel=3D"norefer= rer" target=3D"_blank">https://datatracker.ietf.org/doc/bcp79/</a><br> > [3] <a href=3D"https://datatracker.ietf.org/doc/rfc6701/" rel=3D"noref= errer" target=3D"_blank">https://datatracker.ietf.org/doc/rfc6701/</a><br> > <br> > The IETF datatracker status page for this Internet-Draft is:<br> > <a href=3D"https://datatracker.ietf.org/doc/draft-ietf-spring-srv6-sec= urity/" rel=3D"noreferrer" target=3D"_blank">https://datatracker.ietf.org/d= oc/draft-ietf-spring-srv6-security/</a><br> > <br> > There is also an HTML version available at:<br> > <a href=3D"https://www.ietf.org/archive/id/draft-ietf-spring-srv6-secu= rity-14.html" rel=3D"noreferrer" target=3D"_blank">https://www.ietf.org/arc= hive/id/draft-ietf-spring-srv6-security-14.html</a><br> > <br> > A diff from the previous version is available at:<br> > <a href=3D"https://author-tools.ietf.org/iddiff?url2=3Ddraft-ietf-spri= ng-srv6-security-14" rel=3D"noreferrer" target=3D"_blank">https://author-to= ols.ietf.org/iddiff?url2=3Ddraft-ietf-spring-srv6-security-14</a><br> > <br> > _______________________________________________<br> > spring mailing list -- <a href=3D"mailto:[email protected]" target=3D"_b= lank">[email protected]</a><br> > To unsubscribe send an email to <a href=3D"mailto:[email protected]= g" target=3D"_blank">[email protected]</a><br> <br> </blockquote></div></div> --000000000000995f4906530a57dd-- --===============3147002658211938018== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc3ByaW5nIG1h aWxpbmcgbGlzdCAtLSBzcHJpbmdAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFp bCB0byBzcHJpbmctbGVhdmVAaWV0Zi5vcmcK --===============3147002658211938018==--