[Gen-art] genart review: draft-salowey-tls-rfc4507bis-00

Robert Sparks <rjsparks@nostrum.com> Tue, 21 August 2007 20:16 UTC

Return-path: <gen-art-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1INa8y-0003WE-4O; Tue, 21 Aug 2007 16:16:04 -0400
Received: from gen-art by megatron.ietf.org with local (Exim 4.43) id 1INa8x-0003W8-6y for gen-art-confirm+ok@megatron.ietf.org; Tue, 21 Aug 2007 16:16:03 -0400
Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1INa8w-0003W0-T8 for gen-art@ietf.org; Tue, 21 Aug 2007 16:16:02 -0400
Received: from shaman.nostrum.com ([72.232.15.10] helo=nostrum.com) by chiedprmail1.ietf.org with esmtp (Exim 4.43) id 1INa8w-0002qu-Ga for gen-art@ietf.org; Tue, 21 Aug 2007 16:16:02 -0400
Received: from [172.17.1.65] (vicuna-alt.estacado.net [75.53.54.121]) (authenticated bits=0) by nostrum.com (8.14.1/8.14.1) with ESMTP id l7LKFw5C001549 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Tue, 21 Aug 2007 15:15:58 -0500 (CDT) (envelope-from rjsparks@nostrum.com)
Mime-Version: 1.0 (Apple Message framework v752.3)
Content-Transfer-Encoding: 7bit
Message-Id: <40677B9E-AA89-4C9B-B626-3012CC458B01@nostrum.com>
Content-Type: text/plain; charset="US-ASCII"; delsp="yes"; format="flowed"
To: gen-art@ietf.org, jsalowey@cisco.com, hzhou@cisco.com, pasi.eronen@nokia.com, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
From: Robert Sparks <rjsparks@nostrum.com>
Date: Tue, 21 Aug 2007 15:15:56 -0500
X-Mailer: Apple Mail (2.752.3)
Received-SPF: pass (nostrum.com: 75.53.54.121 is authenticated by a trusted mechanism)
X-Virus-Scanned: ClamAV version 0.91.2, clamav-milter version 0.91.2 on shaman.nostrum.com
X-Virus-Status: Clean
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 21c69d3cfc2dd19218717dbe1d974352
Cc:
Subject: [Gen-art] genart review: draft-salowey-tls-rfc4507bis-00
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/gen-art>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
Errors-To: gen-art-bounces@ietf.org

I have been selected as the General Area Review Team (Gen-ART)
reviewer for this draft (for background on Gen-ART, please see
http://www.alvestrand.no/ietf/gen/art/gen-art-FAQ.html).

Please resolve these comments along with any other Last Call comments
you may receive.


Document: draft-salowey-tls-rfc4507bis-00
Reviewer: Robert Sparks
Review Date: 21Aug07
IETF LC End Date: 22Aug07
IESG Telechat date: (if known)

Summary: This draft is basically ready for publication as proposed  
standard. It has some
minor nits to consider prior to publication.

Comments:

1) The first paragraph of section 3 says:
        This specification defines a mechanism .... (implying one)
        Implementations ... are expected to support both mechanisms.  
(implying two)
      What are the two mechanisms? Could this introduction be phrased  
to make that more obvious?


2) The caption for figure 2 is misformatted (and contains TAB  
characters)

3) Should the references to 2246 at the bottom of page 5 and in  
Sections 5.6 point to 4346 instead?

I also was curious about whether the cookie approach to detecting  
4507 clients introduced any new
points of vulnerability, but I'm not the person to do that analysis  
so I asked ekr. When you were putting
this together, did you have any discussion about that? Apologies if  
it's just dead obvious there's no
potential issue.

RjS



_______________________________________________
Gen-art mailing list
Gen-art@ietf.org
https://www1.ietf.org/mailman/listinfo/gen-art