Re: [Gen-art] Gen-ART LC review of draft-harkins-ipsecme-spsk-auth-03

"Dan Harkins" <dharkins@lounge.org> Fri, 22 April 2011 00:39 UTC

Return-Path: <dharkins@lounge.org>
X-Original-To: gen-art@ietfc.amsl.com
Delivered-To: gen-art@ietfc.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfc.amsl.com (Postfix) with ESMTP id E1C24E0675; Thu, 21 Apr 2011 17:39:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.265
X-Spam-Level:
X-Spam-Status: No, score=-6.265 tagged_above=-999 required=5 tests=[AWL=-0.000, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([208.66.40.236]) by localhost (ietfc.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id anybBKxyCcln; Thu, 21 Apr 2011 17:39:11 -0700 (PDT)
Received: from colo.trepanning.net (colo.trepanning.net [69.55.226.174]) by ietfc.amsl.com (Postfix) with ESMTP id 42A52E065C; Thu, 21 Apr 2011 17:39:11 -0700 (PDT)
Received: from www.trepanning.net (localhost [127.0.0.1]) by colo.trepanning.net (Postfix) with ESMTP id AEF281022404C; Thu, 21 Apr 2011 17:39:10 -0700 (PDT)
Received: from 69.12.173.8 (SquirrelMail authenticated user dharkins@lounge.org) by www.trepanning.net with HTTP; Thu, 21 Apr 2011 17:39:10 -0700 (PDT)
Message-ID: <9a944e460983182912fe0d2e85ef32f9.squirrel@www.trepanning.net>
In-Reply-To: <4da2f037.cf03d90a.5d44.fffff941@mx.google.com>
References: <4da2f037.cf03d90a.5d44.fffff941@mx.google.com>
Date: Thu, 21 Apr 2011 17:39:10 -0700
From: Dan Harkins <dharkins@lounge.org>
To: Roni Even <ron.even.tlv@gmail.com>
User-Agent: SquirrelMail/1.4.14 [SVN]
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
Importance: Normal
X-Mailman-Approved-At: Thu, 21 Apr 2011 17:40:44 -0700
Cc: gen-art@ietf.org, 'IETF-Discussion list' <ietf@ietf.org>, draft-harkins-ipsecme-spsk-auth.all@tools.ietf.org
Subject: Re: [Gen-art] Gen-ART LC review of draft-harkins-ipsecme-spsk-auth-03
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/gen-art>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Apr 2011 00:39:12 -0000

  Hi Roni,

  Thank you for reviewing my draft. Comments inline....

On Mon, April 11, 2011 5:11 am, Roni Even wrote:
> I am the assigned Gen-ART reviewer for this draft. For background on
> Gen-ART, please see the FAQ at
> <http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq>.
>
> Please resolve these comments along with any other Last Call comments you
> may receive.
>
> Minor issues:
>
> 1.	In section 8.5 and 8.6 the draft says that "If no more password
> pre-processing techniques are supported the exchange MUST be
> terminated."
> Reading section 6, I thought that NONE MUST be supported for
> interoperability purpose.

  One of the valid techniques for password pre-processing is "none".
That doesn't mean that there isn't a technique, it means the technique
is to perform no pre-processing on the password (treat it as a raw
blob of bits).

> 2.	In section 8.1 and in figure 1 and figure 2 is there a maximum value
> for "counter"?

  No there isn't, but it is doubtful the number will get very large.
The probability that more than n iterations is necessary will be
roughly (1-(r/2p))^n, where r is the order and p is the prime, and
that number rapidly approaches zero as n increases.

> Nits/editorial comments:
>
> 1.       In section 1 just before 1.1 you have "suceed" instead of
> "succeed"
>
> 2.       In section 4 third bullet "an" instead of "and"
>
> 3.       In section 4.2 "Two elementx" instead of "Two elements"
>
> 4.       In section 5 second row "authenticaiton" should be
> "authentication"
>
> 5.       In section 6 fourth row "identitcal" instead of "identical"

  Thank you for catching all of these.

  regards,

  Dan.