Hi Hemant/Jeff, 

Thank you for the effort put in this document.

Please find below some comments that I prefer we discuss early in the process 
rather than late:

(1) Do we need another PS document for the specific use of TCP-AO with BMP? I'm 
asking the question given that rfc5925#section-1.2 already says:

   >> TCP-AO SHOULD be implemented where the protection afforded by TCP
   authentication is needed, because either IPsec is not supported or
   TCP-AO's particular properties are needed (e.g., per-connection
I note that the reco in the draft covers both the "use" and "support", though. 
The "use" part smells more like a BCP?

(2) BTW, the reco in the draft **seems** to conflict with parts of the 
applicability in rfc5925#section-1.2:

   The implementation and use of TCP-AO to protect BMP session is
   RECOMMENDED in circumstances where the session might not otherwise be
   protected by alternative mechanisms such as IPsec.


   TCP-AO is not intended to replace the use of the IPsec suite (IPsec
   and Internet Key Exchange Protocol (IKE)) to protect TCP connections

It would be better to tweak the reco text to adhere to the applicability scope 
in rfc5925 not weaking it. For example,

   The use of TCP-AO to protect BMP session is
   RECOMMENDED per the applicability scope in Section 1.2 of [RFC5925].

Note that you have it right in Section 4:

   TCP-AO is not intended as a direct substitute for IPsec, nor is it
   suggested as such in this document.

(3) The document is tagged as it updates RFC 7854, but I don't see which part 
this is amending/extending. Even for IPsec, RFC7854 uses this wording: 

   Where the security considerations outlined above are a concern, users
   of this protocol should use IPsec [RFC4303] in tunnel mode with pre-
   shared keys.

Please note also that the base TCP spec (RFC9293) discusses TCP-AO in 

One minor comment about the motivation section: 

* " However, the security
   considerations associated with BMP have become increasingly critical
   in light of evolving threats."

Can we please explicit these threats or simply add pointers?

Thank you.


