Robert, thank you for your review.

And thanks all for your engagement to resolve the issue raised by Robert.

Alissa

> On Apr 7, 2017, at 4:24 PM, Robert Sparks <[email protected]> wrote:
> 
> Reviewer: Robert Sparks
> Review result: Ready with Issues
> 
> I am the assigned Gen-ART reviewer for this draft. The General Area
> Review Team (Gen-ART) reviews all IETF documents being processed
> by the IESG for the IETF Chair.  Please treat these comments just
> like any other last call comments.
> 
> For more information, please see the FAQ at
> 
> <https://trac.ietf.org/trac/gen/wiki/GenArtfaq>.
> 
> Document: draft-ietf-isis-auto-conf-04
> Reviewer: Robert Sparks
> Review Date: 2017-04-07
> IETF LC End Date: 2017-04-10
> IESG Telechat date: 2017-04-13
> 
> Summary: Ready for publication as Proposed Standard, but with 
> one possible thing to add to the security consideration section
> 
> This document is clear and seems straightforward to implement. 
> 
> I think, however, there is an attack possibility you should call out 
> in the security considerations section. As home routers are used 
> as examples of elements that might use this protocol, consider 
> the case of a malicious party wanting to deny service in that home.
> A suborned device in the home could watch for the protocol, and
> present a crafted packet to force the home router(s) to re-start
> the autoconfiguration protocol continually (by claiming to be a
> duplicate and being careful to make it the routers job to restart).
> Having the md5 password configured would mitigate this attack.
> 
> _______________________________________________
> Gen-art mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/gen-art

_______________________________________________
Gen-art mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/gen-art

Reply via email to