[Dime] Ben Campbell's No Objection on draft-ietf-dime-4over6-provisioning-04: (with COMMENT)

"Ben Campbell" <ben@nostrum.com> Wed, 05 August 2015 19:58 UTC

Return-Path: <ben@nostrum.com>
X-Original-To: dime@ietfa.amsl.com
Delivered-To: dime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 204E71A016C; Wed, 5 Aug 2015 12:58:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Uiq5qaA1tFSI; Wed, 5 Aug 2015 12:58:35 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 019F71A0372; Wed, 5 Aug 2015 12:58:31 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Ben Campbell <ben@nostrum.com>
To: The IESG <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.3.0.p1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150805195831.24117.11508.idtracker@ietfa.amsl.com>
Date: Wed, 05 Aug 2015 12:58:31 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/dime/yX0PyBv3G6n-nWp7YWNhFUQKWsI>
Cc: draft-ietf-dime-4over6-provisioning@ietf.org, dime-chairs@ietf.org, dime@ietf.org, draft-ietf-dime-4over6-provisioning.shepherd@ietf.org, draft-ietf-dime-4over6-provisioning.ad@ietf.org
Subject: [Dime] Ben Campbell's No Objection on draft-ietf-dime-4over6-provisioning-04: (with COMMENT)
X-BeenThere: dime@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Diameter Maintanence and Extentions Working Group <dime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dime>, <mailto:dime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dime/>
List-Post: <mailto:dime@ietf.org>
List-Help: <mailto:dime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dime>, <mailto:dime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Aug 2015 19:58:37 -0000

Ben Campbell has entered the following ballot position for
draft-ietf-dime-4over6-provisioning-04: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-dime-4over6-provisioning/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thanks for an easy-to-read document. I have a few questions and comments,
that I hope can be resolve easily:

-- 3.2:
Is it possible (or reasonable) for the FQDN to include an
internationalized domain name? That is, is there a need for a idn or
precis dependency? (I'm not saying there _is_ such a need; I'm just
asking.)

-- 6.1, 2nd paragraph:

So you mean MiTM attacks _on_ peers, or _by_ peers? I assume the second,
since the first can be mitigated with TLS. (I’m not sure I would call
this a MiTM per se, it’s just an issue that compromised or malicious
nodes already in the path may do bad things.)

-- 6.2:
Thanks for including this--but I think it needs a bit more.  I assume
from these sections that some of these AVPs are "security-sensitive" as
defined in the referenced section of RFC 6733. That section invokes
requirements to use mutually authenticated TLS or IPSec, and to be sure
that messages do not traverse any nodes that are not explicitly trusted.
It would be good to explicitly list which AVPs from this draft qualify as
such (unless the answer is "all of them"), and to explicitly mention that
the additional requirements apply to their use.