Robert, thank you for your review. And thanks all for your engagement to resolve the issue raised by Robert.
Alissa > On Apr 7, 2017, at 4:24 PM, Robert Sparks <[email protected]> wrote: > > Reviewer: Robert Sparks > Review result: Ready with Issues > > I am the assigned Gen-ART reviewer for this draft. The General Area > Review Team (Gen-ART) reviews all IETF documents being processed > by the IESG for the IETF Chair. Please treat these comments just > like any other last call comments. > > For more information, please see the FAQ at > > <https://trac.ietf.org/trac/gen/wiki/GenArtfaq>. > > Document: draft-ietf-isis-auto-conf-04 > Reviewer: Robert Sparks > Review Date: 2017-04-07 > IETF LC End Date: 2017-04-10 > IESG Telechat date: 2017-04-13 > > Summary: Ready for publication as Proposed Standard, but with > one possible thing to add to the security consideration section > > This document is clear and seems straightforward to implement. > > I think, however, there is an attack possibility you should call out > in the security considerations section. As home routers are used > as examples of elements that might use this protocol, consider > the case of a malicious party wanting to deny service in that home. > A suborned device in the home could watch for the protocol, and > present a crafted packet to force the home router(s) to re-start > the autoconfiguration protocol continually (by claiming to be a > duplicate and being careful to make it the routers job to restart). > Having the md5 password configured would mitigate this attack. > > _______________________________________________ > Gen-art mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/gen-art _______________________________________________ Gen-art mailing list [email protected] https://www.ietf.org/mailman/listinfo/gen-art
