Title: Response re: draft Technical Report XSTR.srsec and coordination with 
IETF SPRING WG
Submission Date: 2026-08-04
URL of the IETF Web page: https://datatracker.ietf.org/liaison/2209/

To: ITU-T SG 17
From: Source Packet Routing in Networking (spring)
Purpose: In response


Email Addresses
---------------
From: Scott Mansfield <[email protected]>
To: 
[email protected],[email protected],[email protected],[email protected],[email protected]
Cc: Jim Guichard <[email protected]>,Alvaro Retana 
<[email protected]>,Ketan Talaulikar <[email protected]>,Scott 
Mansfield <[email protected]>,Joel Halpern 
<[email protected]>,Source Packet Routing in Networking Discussion List 
<[email protected]>,Bruno Decraene <[email protected]>,Gunter Van de 
Velde <[email protected]>
Response Contacts: Bruno Decraene <[email protected]>,Alvaro Retana 
<[email protected]>,Joel Halpern <[email protected]>
Technical Contacts: Alvaro Retana <[email protected]>


Referenced liaison: LS on the progress and coordination on draft Technical 
Report ITU-T XSTR.srsec related to segment routing IPv6 (SRv6) security in 
ITU-T Study Group 17 (https://datatracker.ietf.org/liaison/2201/)

Body: Dear ITU-T SG17 colleagues,

Thank you for the Liaison Statement. We are glad to provide an update on the 
status of SRv6 security work in the IETF, as requested.

As is required practice in the IETF, all documents include Security 
Considerations. Specifically, all SRv6-related documents, including extensions, 
include specific Security Considerations.

Additionally, the SPRING  Working Group is developing a standalone document on 
the topic. "Segment Routing IPv6 Security Considerations" 
(draft-ietf-spring-srv6-security) is currently in Working Group Last Call in 
the SPRING Working Group, which is the final stage of WG review before it is 
submitted for IETF-wide and IESG review on the way to publication as an RFC. It 
represents mature, near-consensus text on this topic.

draft-ietf-spring-srv6-security-16 (the current revision) addresses every 
SRv6-specific topic covered in XSTR.srsec — including information 
leakage/reconnaissance, resource abuse and SID/policy tampering, resource 
exhaustion, and the recommended countermeasures (HMAC-based integrity 
protection, trusted-domain/address filtering, encrypted control-plane channels) 
— generally in more depth and with more detailed threat and mitigation 
taxonomies. The additional risks XSTR.srsec discusses (e.g., LLDP-based 
topology poisoning, controller impersonation, flow-table exhaustion, network 
fingerprinting) are specific to particular SDN-controller/NFV deployment 
architectures rather than to SRv6 itself, and so fall outside the scope of an 
SRv6-focused analysis.

Given the substantial overlap, we believe the most effective path for continued 
coordination is for SG17 experts to engage directly with 
draft-ietf-spring-srv6-security while it is still open for comment. We warmly 
invite SG17 to:

  - Review draft-ietf-spring-srv6-security-16; [1]

  - Raise any gaps, disagreements, or additional considerations on the SPRING 
Working Group mailing list ([email protected]), during the Working Group Last 
Call or IETF Last Call periods.

We believe this is the best way to ensure a single, consistent, and 
authoritative treatment of SRv6 security considerations that both organizations 
can reference going forward, and we look forward to SG17's input on the SPRING 
mailing list.

Best regards,

Alvaro Retana 
Chair, SPRING Working Group, IETF (on behalf of the SPRING WG chairs)

[1] https://datatracker.ietf.org/doc/draft-ietf-spring-srv6-security/
Attachments:

No document has been attached


_______________________________________________
spring mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to