Re: [Gen-art] Gen-ART last call review of draft-ietf-marf-authfailure-report-07

Alexey Melnikov <alexey.melnikov@isode.com> Sun, 01 January 2012 21:09 UTC

Return-Path: <alexey.melnikov@isode.com>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F08F21F0C3B; Sun, 1 Jan 2012 13:09:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.483
X-Spam-Level:
X-Spam-Status: No, score=-102.483 tagged_above=-999 required=5 tests=[AWL=0.116, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zscQhAu5Tn8r; Sun, 1 Jan 2012 13:09:01 -0800 (PST)
Received: from rufus.isode.com (cl-125.lon-03.gb.sixxs.net [IPv6:2a00:14f0:e000:7c::2]) by ietfa.amsl.com (Postfix) with ESMTP id DC78D1F0C36; Sun, 1 Jan 2012 13:09:00 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1325452140; d=isode.com; s=selector; i=@isode.com; bh=cwzbZZU8tDOeHEH6G08jcnbkczY+Ewds+xY7UUodXKc=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=PN4ICQVtZpFFYbQcz5E2+60xqMz+/PkApCShUKT1BBsxprCR7gTZBjiMuk7LVkAe+37UE0 CvqyVkSe921q57VkRSp1pDOdxesBaBXNVF//0ucJ9vJuXx4Mi31/Nm2LDNJQbUAVHt7MNv jpF39rTA53lI9GTm46mBfEb+b0LyOeo=;
Received: from [192.168.0.109] ((unknown) [109.73.6.25]) by rufus.isode.com (submission channel) via TCP with ESMTPSA id <TwDLagBr13jh@rufus.isode.com>; Sun, 1 Jan 2012 21:08:59 +0000
X-SMTP-Protocol-Errors: NORDNS
Message-ID: <4F00CB67.3080306@isode.com>
Date: Sun, 01 Jan 2012 21:08:55 +0000
From: Alexey Melnikov <alexey.melnikov@isode.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:8.0) Gecko/20111105 Thunderbird/8.0
To: "Murray S. Kucherawy" <msk@cloudmark.com>
References: <4F00C250.4000508@isode.com> <F5833273385BB34F99288B3648C4F06F19C6C156B8@EXCH-C2.corp.cloudmark.com>
In-Reply-To: <F5833273385BB34F99288B3648C4F06F19C6C156B8@EXCH-C2.corp.cloudmark.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Cc: Pete Resnick <presnick@qualcomm.com>, "Hilda L. Fontana" <hilda@hfontana.com>, "gen-art@ietf.org" <gen-art@ietf.org>, The IESG <iesg@ietf.org>
Subject: Re: [Gen-art] Gen-ART last call review of draft-ietf-marf-authfailure-report-07
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/gen-art>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 01 Jan 2012 21:09:02 -0000

On 01/01/2012 20:57, Murray S. Kucherawy wrote:
>> -----Original Message-----
>> From: Alexey Melnikov [mailto:alexey.melnikov@isode.com]
>> Sent: Sunday, January 01, 2012 12:30 PM
>> To: Hilda L. Fontana; Murray S. Kucherawy; Pete Resnick
>> Cc: gen-art@ietf.org; The IESG
>> Subject: Gen-ART last call review of draft-ietf-marf-authfailure-
>> report-07
> Hi Alexey,
Hi Murray,
>
>> Major issues:
>>
>> I understand that this is a bit pedantic, but ID-nits reports the
>> following:
>>
>>     ** Downref: Normative reference to an Experimental RFC: RFC 4408
>> (ref.
>>        'SPF')
>>
>> and this was not called out during the IETF LC announcement.
>> This reference is truly Normative, so just making it Informative
>> wouldn't work.
> Yep, this was pointed out by someone else too.  I missed it during my shepherd write-up.  It's been moved to the 1/19 telechat, partly because we'll probably need a second LC to handle this properly.
Yep.
>> Minor issues:
>>
>> 1. Introduction
>>
>> [ARF] defines a message format for sending reports of abuse in the
>> messaging infrastructure, with an eye towards automating both the
>> generation and consumption of those reports. There is now also a desire
>> to extend the ARF format to include reporting of messages that fail to
>> authenticate using known authentication methods, as these are sometimes
>> evidence of abuse that can be detected and reported through automated
>> means. The same mechanism can be used to convey forensic information
>> about the specific reason the authentication method failed. Thus, this
>> memo presents such extensions to the Abuse Reporting Format to allow
>> for detailed reporting of message authentication method failures.
>>
>> Maybe that is just me, but when I read "message authentication" I don't
>> really have a clue what you are talking about. I needed to read the
>> rest of the document in order to understand its scope.
> Rather than adding a paragraph or two about what message authentication is, would it be sufficient to add references to the SPF and DKIM specifications, and perhaps the DKIM Threats document, to the second sentence above (a la "such as...")?
That would be fine.
(I originally was asking myself if TLS and SASL authentication was in 
scope, but it is clearly isn't.)
> I'm weary of adding text that repeats what's stated elsewhere and would prefer we just add some references to appropriate reading.
>
>> 2.2. Base 64
>>
>> base64 is defined in [MIME].
I forgot to mention: It might be worth referencing the base64 RFC instead.

  [...]