[COSE] Paul Wouters' Yes on draft-ietf-cose-countersign-10: (with COMMENT)

Paul Wouters via Datatracker <noreply@ietf.org> Tue, 20 September 2022 19:58 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: cose@ietf.org
Delivered-To: cose@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 0E534C1524B8; Tue, 20 Sep 2022 12:58:30 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Paul Wouters via Datatracker <noreply@ietf.org>
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-cose-countersign@ietf.org, cose-chairs@ietf.org, cose@ietf.org, mcr+ietf@sandelman.ca, mcr+ietf@sandelman.ca
X-Test-IDTracker: no
X-IETF-IDTracker: 8.16.0
Auto-Submitted: auto-generated
Precedence: bulk
Reply-To: Paul Wouters <paul.wouters@aiven.io>
Message-ID: <166370391005.12830.10875322543308287729@ietfa.amsl.com>
Date: Tue, 20 Sep 2022 12:58:30 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/qCXTRYpfTMCdZLDOHW7a0_Xvwjs>
Subject: [COSE] Paul Wouters' Yes on draft-ietf-cose-countersign-10: (with COMMENT)
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.39
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Sep 2022 19:58:30 -0000

Paul Wouters has entered the following ballot position for
draft-ietf-cose-countersign-10: Yes

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ 
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-cose-countersign/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thanks for addressing my DISCUSS. I updated my ballot to YES.

Old DISCUSS:

        gem install cbor-diag

I am concerned about adding install commands for "programs from the internet"
within an RFC. If the rubygem for some reason becomes malicious, we cannot
pull it from the RFC (even if we pull it from the datatracker link, it would
still live on in copies of the RFC elsewhere and malicious people could point
to copies of those original RFCs to point people to downlod the malicious rubygem.

I would be okay with an iet.org download location of a ruby gem.

NITS:

        CBOR grammar in this document is uses

Remove "is"

        to deal with &gt; as an entity

This is a render error for '>'  ?

        they apply

these apply

        Languages: There are three different languages that are currently
        supported: Java and C#.

That's two not three? Text below suggests there might be a 3rd one in C ?