Re: [Gen-art] review of draft-turner-md5-seccon-update-07.txt

Sean Turner <turners@ieca.com> Fri, 10 December 2010 14:19 UTC

Return-Path: <turners@ieca.com>
X-Original-To: gen-art@core3.amsl.com
Delivered-To: gen-art@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 8A72B28C0F6 for <gen-art@core3.amsl.com>; Fri, 10 Dec 2010 06:19:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.038
X-Spam-Level:
X-Spam-Status: No, score=-102.038 tagged_above=-999 required=5 tests=[AWL=-0.040, BAYES_00=-2.599, J_CHICKENPOX_12=0.6, UNPARSEABLE_RELAY=0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cw247AGHp3yT for <gen-art@core3.amsl.com>; Fri, 10 Dec 2010 06:19:21 -0800 (PST)
Received: from nm5.bullet.mail.ne1.yahoo.com (nm5.bullet.mail.ne1.yahoo.com [98.138.90.68]) by core3.amsl.com (Postfix) with SMTP id 12A2F28C0F2 for <gen-art@ietf.org>; Fri, 10 Dec 2010 06:19:20 -0800 (PST)
Received: from [98.138.90.52] by nm5.bullet.mail.ne1.yahoo.com with NNFMP; 10 Dec 2010 14:20:43 -0000
Received: from [98.138.89.161] by tm5.bullet.mail.ne1.yahoo.com with NNFMP; 10 Dec 2010 14:20:43 -0000
Received: from [127.0.0.1] by omp1017.mail.ne1.yahoo.com with NNFMP; 10 Dec 2010 14:20:43 -0000
X-Yahoo-Newman-Id: 770248.84880.bm@omp1017.mail.ne1.yahoo.com
Received: (qmail 43458 invoked from network); 10 Dec 2010 14:20:43 -0000
Received: from thunderfish.local (turners@71.191.15.81 with plain) by smtp111.biz.mail.mud.yahoo.com with SMTP; 10 Dec 2010 06:20:42 -0800 PST
X-Yahoo-SMTP: ZrP3VLSswBDL75pF8ymZHDSu9B.vcMfDPgLJ
X-YMail-OSG: MGdvM6YVM1ni1Yv0VMMmsRMC2fGtf6vA9e3qUSFphMpKuUc FNuhefjs480oIrHbybR8lDlGGbtcCT.YjouMbVQgfE1mglJLJy3Yo7Se52CL g29Nkn8HWzPOf_UeDRjdkDOOox9yB_VYFiH2aoaIbF_OHz66nfrIHz2zfBS0 mQlOuu2Elwnu3YvJt5kAwsTC5O_MPrVTohlKt8jtrVKIdjc1DzXjGwP74Jb3 .nPxOe67VzPabg0Q27ZyBHS98j3TRUWyPTUgX.Edl50sPAuqOKQDdQm7vwzv lFr0WSZYVuyQOPcnQIlQJhNHhWlOP1GBIgcpy5b21x.z4T5wc2BhHHaAEXs9 7Ky6m79fd3923CgHl8_nFu3_rdpY0Mz1ceh8dEo.B
X-Yahoo-Newman-Property: ymail-3
Message-ID: <4D023732.3090009@ieca.com>
Date: Fri, 10 Dec 2010 09:20:34 -0500
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2.12) Gecko/20101027 Lightning/1.0b2 Thunderbird/3.1.6
MIME-Version: 1.0
To: Francis Dupont <Francis.Dupont@fdupont.fr>
References: <201012100945.oBA9jbll092567@givry.fdupont.fr>
In-Reply-To: <201012100945.oBA9jbll092567@givry.fdupont.fr>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Cc: gen-art@ietf.org, draft-turner-md5-seccon-update.all@tools.ietf.org
Subject: Re: [Gen-art] review of draft-turner-md5-seccon-update-07.txt
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/gen-art>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 10 Dec 2010 14:19:22 -0000

Francis,

Thanks for your review.  Responses inline.

spt

On 12/10/10 4:45 AM, Francis Dupont wrote:
> I am the assigned Gen-ART reviewer for this draft. For background on
> Gen-ART, please see the FAQ at<
> http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq>.
>
> Please resolve these comments along with any other Last Call comments you
> may receive.
>
> Document: draft-turner-md5-seccon-update-07.txt
> Reviewer: Francis Dupont
> Review Date: 2010-12-06
> IETF LC End Date: 2010-12-22
> IESG Telechat date: unknown
>
> Summary: Not Ready
>
> Major issues:
>   - IANA action is to change a field which doesn't exist

Paul Hoffman suggested that the IANA considerations be changed to 
"None."  The hash algorithm textual name registry really ought to be 
updated by the folks who registered it not in this outlier document and 
without some context the values like "deprecated" (see next issue) 
really doesn't make any sense to stick in a registry.

FYI - the registry was updated in draft-turner-md2-to-historic - and 
there was NO way for you to know that (sorry about the confusion).  I'm 
going to make that IANA consideration "None" too.

>   - there is no consensus if the document should stress not-security uses
>    of MD5 are perfectly fine or at the opposite the security label attached
>    to MD5 raises practical issues so new uses of MD5 should be strongly
>    discouraged or both are out of scope...

Yeah not sure how I'm going to "solve" this one.  I'll propose some text 
and see what happens.

> Minor issues: None
>
> Nits/editorial comments:
>   - 2.1 page 2: Psuedo ->  Pseudo
>
>   - 2.1 page 3: 1.6 GHz. ->  1.6GHz (note: suggestion for removing the space,
>    fix for the spurious '.' after an unit)
>
>   - 2.3 page 3: (suggestion) H(IV,M). ->  H(IV, M).

Will fix up.

> Regards
>
> Francis.Dupont@fdupont.fr
>
> PS: about 3:
>
>     IANA is requested to update the md5 usage entry in the Hash Function
>     Textual Names registry by replacing "COMMON" with "DEPRECATED".
>
> I understand why the md5 is in lower case (it is the name of the entry)
> but I can't find the usage field in the registry at:

As noted about, the registry was updated in another draft 
draft-turner-md2-to-historic.  Making them "None" ought to solve this 
problem.

> http://www.iana.org/assignments/hash-function-text-names/
> hash-function-text-names.xhtml
>
> PPS: my proposal for solving the two issues is:
>   - give the first one to IANA (IANA has to address it anyway)
>    (PS: in fact IANA already raised a question about this point!)
>   - use the standard Last Call process for the second