Document: draft-ietf-ipsecme-ikev2-downgrade-prevention
Title: Downgrade Prevention for the Internet Key Exchange Protocol Version 2
(IKEv2) Reviewer: Dhruv Dhody Review result: Has Issues

Hi,

I have been selected as the Operational Directorate (opsdir) reviewer for this
Internet-Draft.

The Operational Directorate reviews all operational and management-related
Internet-Drafts to ensure alignment with operational best practices and that
adequate operational considerations are covered.

A complete set of _"Guidelines for Considering Operations and Management in
IETF Specifications"_ can be found at
https://datatracker.ietf.org/doc/draft-ietf-opsawg-rfc5706bis/.

While these comments are primarily for the Operations and Management Area
Directors (Ops ADs), the authors should consider them alongside other feedback
received.

**Document**: draft-ietf-ipsecme-ikev2-downgrade-prevention-05

**Reviewer**: Dhruv Dhody

**Review Date**: 2026-06-09

**Intended Status**: Standards Track

---

## **Summary**

I have some **minor** concerns about this document, but it is otherwise ready.

## **General Operational Comments Alignment with RFC 5706bis**

This document defines a mechanism for preventing downgrade attacks on IKEv2.
While the technical approach is sound, it lacks an explicit operational
considerations section.

The authors could consider adding a brief section if they feel there is useful
operational guidance to be provided for upgrading to this extension,
interoperability with legacy RFC7296 or on detecting & logging attempts of
downgrade attack (is it even possible?), etc.

## **Minor Issues**

- Section 1, consider clarifying "the data to be authenticated" means in the
context of this document.

- Section 6, is it possible to clearly identify what text from RFC 7296 is
being modified because of the update tag

- Section 7, are you updating text in RFC 9242 or RFC 5723? If yes, then we
should use the update tag; if not, it should be clearer to the reader why RFC
7296 is the only one being updated.

## **Nits**

- Section 1, s/RFC 7296/[RFC7296]/

Thank you for your work on this document. Please address these comments, or
feel free to contact me for clarification and/or discussion.

Thanks!
Dhruv


_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to