[Gen-art] Genart telechat review of draft-ietf-tls-dnssec-chain-extension-06

Matthew Miller <linuxwolf+ietf@outer-planes.net> Wed, 07 February 2018 01:25 UTC

Return-Path: <linuxwolf+ietf@outer-planes.net>
X-Original-To: gen-art@ietf.org
Delivered-To: gen-art@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id CE05912DA22; Tue, 6 Feb 2018 17:25:59 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Matthew Miller <linuxwolf+ietf@outer-planes.net>
To: gen-art@ietf.org
Cc: ietf@ietf.org, draft-ietf-tls-dnssec-chain-extension.all@ietf.org, tls@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.72.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151796675979.25928.2038193051971303546@ietfa.amsl.com>
Date: Tue, 06 Feb 2018 17:25:59 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/gen-art/LVLWFU2Kv8C_4UgwSbipkfh0Aa0>
Subject: [Gen-art] Genart telechat review of draft-ietf-tls-dnssec-chain-extension-06
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Feb 2018 01:26:00 -0000

Reviewer: Matthew Miller
Review result: Ready with Nits

I am the assigned Gen-ART reviewer for this draft. The General Area
Review Team (Gen-ART) reviews all IETF documents being processed
by the IESG for the IETF Chair. Please wait for direction from your
document shepherd or AD before posting a new version of the draft.

For more information, please see the FAQ at

<https://trac.ietf.org/trac/gen/wiki/GenArtfaq>.

Document: draft-ietf-tls-dnssec-chain-extension-06
Reviewer: Matthew A. Miller
Review Date: 2018-02-06
IETF LC End Date: 2018-02-07
IESG Telechat date: 2018-02-08

Summary:

This document is ready, with one issue that I think could benefit
from some clarification.

Major issues:

NONE

Minor issue:

This is more a question, that might warrant some clarification:
In 7. Verification, the last paragraph discusses client-side
caching of the RRsets. If a client has cached the full RRset chain
from TLSA to root RRSIG (and that cache is still viable), is the
client still expected to specify the "dnssec_chain" extension?

In my reading, that does not seem necessary, and I think it might
be worth noting if that is true.

Nits/editorial comments: 

NONE