
   I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG. These comments were written primarily for the benefit of the
security area directors. Document editors and WG chairs should treat
these comments just like any other last call comments.

   The summary of the review is Ready.

   This document defines a way for an enterprise network to obtain
a set of characteristics in a service provider network that will
allow the enterprise network to generate configuration blocks on
devices in the enterprise network in order to ensure a successful
service provider peering. The document specifies an HTTPS-protected
request-response. One thing I found missing (and I think it might
even arise to the level of "nit" but I'm not sure) was a reference
to RFC 8446. Also there was no mention of a required TLS version to
protect the exchange. Might want to consider adding that.

   The document is mature and well-written. The Security Considerations
look thorough, modulo the lack of mention of TLS 1.3 which seems to
be de rigueur these days.



"The object of life is not to be on the side of the majority, but to
escape finding oneself in the ranks of the insane." -- Marcus Aurelius