I reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. This document updates RFC 5586 by retiring ACH TLVs (an MPLS extensibility mechanism) and removing the associated IANA registry. The Security Considerations section states that by removing an unused feature of MPLS security of implementations is improved. I tend to agree, simplicity is a good thing. It also states that the removed feature can be used to secure messages on the G-ACh in a generic way, but that no such mechanism was proposed so far. I think this is a fair comment. I think the Security Considerations section is quite reasonable for this document. I don't have any issues with this document.