[Gen-art] Genart last call review of draft-ietf-lamps-crmf-update-algs-04

Ines Robles via Datatracker <noreply@ietf.org> Fri, 26 March 2021 15:21 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: gen-art@ietf.org
Delivered-To: gen-art@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 3592A3A214A; Fri, 26 Mar 2021 08:21:16 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Ines Robles via Datatracker <noreply@ietf.org>
To: gen-art@ietf.org
Cc: draft-ietf-lamps-crmf-update-algs.all@ietf.org, last-call@ietf.org, spasm@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 7.27.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <161677207615.11612.13922111242017074185@ietfa.amsl.com>
Reply-To: Ines Robles <mariainesrobles@googlemail.com>
Date: Fri, 26 Mar 2021 08:21:16 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/gen-art/JPmmPFesMb8R5GlJ2PUrMJ-Vdx8>
Subject: [Gen-art] Genart last call review of draft-ietf-lamps-crmf-update-algs-04
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.29
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 Mar 2021 15:21:19 -0000

Reviewer: Ines Robles
Review result: Ready with Nits

I am the assigned Gen-ART reviewer for this draft. The General Area
Review Team (Gen-ART) reviews all IETF documents being processed
by the IESG for the IETF Chair.  Please treat these comments just
like any other last call comments.

For more information, please see the FAQ at

<https://trac.ietf.org/trac/gen/wiki/GenArtfaq>.

Document: draft-ietf-lamps-crmf-update-algs-04
Reviewer: Ines Robles
Review Date: 2021-03-26
IETF LC End Date: 2021-03-26
IESG Telechat date: Not scheduled for a telechat

Summary:

The document updates the cryptographic algorithm requirements for the
Password-Based Message Authentication Code in the Internet X.509 Public Key
Infrastructure Certificate Request Message Format (CRMF).

The document is well written, I have minor comments/questions to the authors.

Major Issues: None

Minor Issues: None

Nits/Comments:

1- Introduction: "however, these algorithms are no longer
   considered the best choices. " => It would be nice to add 1 or more
   sentences explaining why they are no longer the best choices

2- Page 3: "id-PasswordBasedMAC as presented in Section 4.4 of this document"
It should be perhaps be "id-PasswordBasedMAC as presented in Section 4.4 of
[RFC4211]" ?

3- If this document does not present privacy considerations, should it be
explicitly mentioned in Section 6?

4- Since the new updates include the use of PBMAC1, HMAC-SHA256, AES-GMAC AES.
Should Section 6 include considerations about them or point to place where to
find them? e.g. For information on security considerations for PBMAC1 see
[rfc8018#section-8].

Thank you for this document,

Ines.