Skip to content

Security Considerations needs to be addressed #15

@ahassany

Description

@ahassany

Security Considerations (Section 7) states: "This document should not affect the security of the Internet." This is inadequate for a Standards Track document. Message Keys expose structural information about the operator's YANG schema deployments and hostname conventions to anyone with access to the Message Broker. The security section should at minimum discuss: (a) Message Broker access control to prevent information leakage via topic names and Message Keys; (b) the risk of Message Key collision attacks degrading partitioning uniformity; and (c) alignment with the security considerations of the referenced RFCs (RFC 8641 §7 discusses access control for push updates in detail).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions