[manet] Re: [secdir] Secdir early review of draft-ietf-m anet-dlep-traffic-classification-12

Shawn M Emery <[email protected]>
Newsgroups gmane.ietf.manet
Message-ID <[email protected]>
In addition to disclosing the DoS attack, I would suggest adding that 
the privacy and integrity of the protocol's messaging is also covered by 
specifying DLEP's TLS option.

Shawn.
--
On 8/10/24 11:52 PM, Shawn Emery via Datatracker wrote:
> Reviewer: Shawn Emery
> Review result: Has Nits
>
> I have reviewed this document as part of the security directorate's ongoing
> effort to review all IETF documents being processed by the IESG. These comments
> were written primarily for the benefit of the security area directors. Document
> editors and WG chairs should treat these comments just like any other last call
> comments.
>
> This standards track draft specifies a protocol for identifying various link
> control messages utilized by the Dynamic Link Exchange Protocol (DLEP).
>
> The security considerations sections does exist and discloses that the protocol
> opens up vulnerabilities for DoS by modifying or injecting protocol messages
> (e.g., decrease the max window size to a unrealistically small value).  The
> mitigation of said vulnerabilities is deferred to RFC 8175's security
> considerations, which prescribes TLS for transport security and provides
> IEEE-802.1AE and IEEE-802.1X as examples to protect Layer 2 from injecting or
> altering messages.  I believe this to be an accurate assertion.
>
> General comments:
>
> In order to help me fully understand the concepts of this protocol I think it
> would be nice to have examples for DSCP and PCP Sub-Data Items.
>
> Editorial comments:
>
> s/DLPE/DLEP/
>
>
> _______________________________________________
> secdir mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> wiki: https://wiki.ietf.org/group/secdir/SecDirReview


_______________________________________________
manet mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.