[Emu] Re: secdir review of draft-simon-emu-rfc2716bis-11.txt

Stephen Farrell <stephen.farrell@cs.tcd.ie> Fri, 21 December 2007 16:23 UTC

Return-path: <emu-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1J5keS-0007sT-4T; Fri, 21 Dec 2007 11:23:08 -0500
Received: from emu by megatron.ietf.org with local (Exim 4.43) id 1J5kWv-0008IV-EY for emu-confirm+ok@megatron.ietf.org; Fri, 21 Dec 2007 11:15:21 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1J5kWu-0008HK-LT for emu@ietf.org; Fri, 21 Dec 2007 11:15:20 -0500
Received: from wpad.iss.tcd.ie ([134.226.1.156] helo=imx2.tcd.ie) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1J5kWr-0001xV-Nu for emu@ietf.org; Fri, 21 Dec 2007 11:15:19 -0500
Received: from Vams.imx2 (imx2.tcd.ie [134.226.1.156]) by imx2.tcd.ie (Postfix) with SMTP id 9AB40681C1; Fri, 21 Dec 2007 16:15:16 +0000 (GMT)
Received: from imx2.tcd.ie ([134.226.1.156]) by imx2.tcd.ie ([134.226.1.156]) with SMTP (gateway) id A045FA96D66; Fri, 21 Dec 2007 16:15:16 +0000
Received: from [134.226.36.180] (sfarrell.dsg.cs.tcd.ie [134.226.36.180]) by imx2.tcd.ie (Postfix) with ESMTP id 8E5E7681C1; Fri, 21 Dec 2007 16:15:16 +0000 (GMT)
Message-ID: <476BE69C.7020103@cs.tcd.ie>
Date: Fri, 21 Dec 2007 16:15:24 +0000
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Thunderbird 2.0.0.9 (Windows/20071031)
MIME-Version: 1.0
To: Bernard Aboba <bernard_aboba@hotmail.com>
References: <BAY117-W2507936795692FAFE3A364935C0@phx.gbl>
In-Reply-To: <BAY117-W2507936795692FAFE3A364935C0@phx.gbl>
X-Enigmail-Version: 0.95.5
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-AntiVirus-Status: MessageID = A145FA96D66
X-AntiVirus-Status: Host: imx2.tcd.ie
X-AntiVirus-Status: Action Taken:
X-AntiVirus-Status: NONE
X-AntiVirus-Status: Checked by TCD Vexira. (version=1.57.6 VDF=9.117.8)
X-Spam-Score: -4.0 (----)
X-Scan-Signature: 7baded97d9887f7a0c7e8a33c2e3ea1b
X-Mailman-Approved-At: Fri, 21 Dec 2007 11:23:07 -0500
Cc: dansimon@microsoft.com, secdir@mit.edu, rmh@microsoft.com, emu@ietf.org
Subject: [Emu] Re: secdir review of draft-simon-emu-rfc2716bis-11.txt
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
Errors-To: emu-bounces@ietf.org


Bernard Aboba wrote:
> Thank you for your detailed comments.
> 
> I have produced an updated version of the document to address these and
> other IETF last call comments:
> http://www.drizzle.com/~aboba/EMU/draft-simon-emu-rfc2716bis-12.txt

Except as noted below those look fine. And since the things below
are ok too, I've no remaining issues with this draft.

Regards,
Stephen.

> - 2.1.3 3rd para says "verify the hash" without saying which hash.
> 
> [BA] I presume we're talking about the Finished message, no? Do we need to
> state that explicitly?

I'd just say "verify the finished message" but its a nit.

> - 2.1.5 is "may be desirable" right? That paragraph seems a bit vague
> overall.
> 
> [rmh] Yes, that is an ok change.
> 
> [BA] Are we talking about the second paragraph?  Is there a suggested
> change in the text?
> 
> "   In order to protect against reassembly lockup and denial of service
>    attacks, it may be desirable for an implementation to set a maximum
>    size for one such group of TLS messages.  Since a single certificate
>    is rarely longer than a few thousand octets, and no other field is
>    likely to be anywhere near as long, a reasonable choice of maximum
>    acceptable message length might be 64 KB."

Actually on re-reading I also it clearer so you can ignore
me here (must've had a bad day before:-)



_______________________________________________
Emu mailing list
Emu@ietf.org
https://www1.ietf.org/mailman/listinfo/emu