Re: draft-ietf-bfd-secure-sequence-numbers (WGLC for the 3 BFD auth documents and IPR check)

2024-06-13 Thread Reshad Rahman
Here are my comments on draft-ietf-bfd-secure-sequence-numbers. I'm not a security expert, so my comments are BFD specific, relying on SecDir for the security aspects.  Section 1   - Nit "parties securely signal" -> "parties to securely signal" Section 3 (updating RFC5880)   - 3rd paragraph says

Re: Secdir early review of draft-ietf-bfd-stability-13

2024-06-13 Thread Reshad Rahman
Chiming in late. Inline. On Monday, June 10, 2024, 12:22:13 PM EDT, Jeffrey Haas wrote: Christian, Thanks for your review.  Some of my comments will overlap those from Alan. On Fri, Jun 07, 2024 at 09:54:57PM -0700, Christian Huitema via Datatracker wrote: > The authentication sequen

Re: Secdir early review of draft-ietf-bfd-stability-13

2024-06-13 Thread Christian Huitema
On 6/13/2024 8:46 AM, Reshad Rahman wrote: Chiming in late. Inline. On Monday, June 10, 2024, 12:22:13 PM EDT, Jeffrey Haas wrote: Christian, Thanks for your review.  Some of my comments will overlap those from Alan. On Fri, Jun 07, 2024 at 09:54:57PM -0700, Christian Huitema

Re: draft-ietf-bfd-secure-sequence-numbers (WGLC for the 3 BFD auth documents and IPR check)

2024-06-13 Thread Alan DeKok
On Jun 13, 2024, at 11:04 AM, Reshad Rahman wrote: > Here are my comments on draft-ietf-bfd-secure-sequence-numbers. I'm not a > security expert, so my comments are BFD specific, relying on SecDir for the > security aspects. Some minor replies > Section 3 (updating RFC5880) > > - 3rd pa

Re: draft-ietf-bfd-stability (WGLC for the 3 BFD auth documents and IPR check)

2024-06-13 Thread Reshad Rahman
Here are my comments for draft-ietf-bfd-stability. Regarding the thread with Christian for the SecDir review, I wouldn't want a ban on NULL auth but we should consider his suggestion of using it in certain environments only. Section 7 (YANG module)   - In RFC9314, all packet counts for session