[manet] Re: [secdir] Secdir early review of draft-ietf-m anet-dlep-traffic-classification-12
Shawn M Emery <[email protected]>
| Newsgroups | gmane.ietf.manet |
|---|---|
| Message-ID | <[email protected]> |
In addition to disclosing the DoS attack, I would suggest adding that the privacy and integrity of the protocol's messaging is also covered by specifying DLEP's TLS option. Shawn. -- On 8/10/24 11:52 PM, Shawn Emery via Datatracker wrote: > Reviewer: Shawn Emery > Review result: Has Nits > > I have reviewed this document as part of the security directorate's ongoing > effort to review all IETF documents being processed by the IESG. These comments > were written primarily for the benefit of the security area directors. Document > editors and WG chairs should treat these comments just like any other last call > comments. > > This standards track draft specifies a protocol for identifying various link > control messages utilized by the Dynamic Link Exchange Protocol (DLEP). > > The security considerations sections does exist and discloses that the protocol > opens up vulnerabilities for DoS by modifying or injecting protocol messages > (e.g., decrease the max window size to a unrealistically small value). The > mitigation of said vulnerabilities is deferred to RFC 8175's security > considerations, which prescribes TLS for transport security and provides > IEEE-802.1AE and IEEE-802.1X as examples to protect Layer 2 from injecting or > altering messages. I believe this to be an accurate assertion. > > General comments: > > In order to help me fully understand the concepts of this protocol I think it > would be nice to have examples for DSCP and PCP Sub-Data Items. > > Editorial comments: > > s/DLPE/DLEP/ > > > _______________________________________________ > secdir mailing list -- [email protected] > To unsubscribe send an email to [email protected] > wiki: https://wiki.ietf.org/group/secdir/SecDirReview _______________________________________________ manet mailing list -- [email protected] To unsubscribe send an email to [email protected]