[Gen-art] Gen-ART Last Call review of draft-ietf-rtcweb-stun-consent-freshness-13

Meral Shirazipour <meral.shirazipour@ericsson.com> Fri, 15 May 2015 20:17 UTC

Return-Path: <meral.shirazipour@ericsson.com>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com []) by ietfa.amsl.com (Postfix) with ESMTP id 6BC751A1B84 for <gen-art@ietfa.amsl.com>; Fri, 15 May 2015 13:17:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([]) by localhost (ietfa.amsl.com []) (amavisd-new, port 10024) with ESMTP id 5pN5rCHczOn9 for <gen-art@ietfa.amsl.com>; Fri, 15 May 2015 13:17:41 -0700 (PDT)
Received: from usevmg21.ericsson.net (usevmg21.ericsson.net []) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BB3BC1A070E for <gen-art@ietf.org>; Fri, 15 May 2015 13:17:41 -0700 (PDT)
X-AuditID: c6180641-f79086d000001909-4c-5555efd18424
Received: from EUSAAHC006.ericsson.se (Unknown_Domain []) by usevmg21.ericsson.net (Symantec Mail Security) with SMTP id 4E.E1.06409.1DFE5555; Fri, 15 May 2015 15:08:33 +0200 (CEST)
Received: from EUSAAMB107.ericsson.se ([]) by EUSAAHC006.ericsson.se ([]) with mapi id 14.03.0210.002; Fri, 15 May 2015 16:17:39 -0400
From: Meral Shirazipour <meral.shirazipour@ericsson.com>
To: "draft-ietf-rtcweb-stun-consent-freshness.all@tools.ietf.org" <draft-ietf-rtcweb-stun-consent-freshness.all@tools.ietf.org>, "gen-art@ietf.org" <gen-art@ietf.org>
Thread-Topic: Gen-ART Last Call review of draft-ietf-rtcweb-stun-consent-freshness-13
Thread-Index: AdCPTCeBLwIOGK4OTCGKJsw8iNXzOw==
Date: Fri, 15 May 2015 20:17:38 +0000
Message-ID: <ABCAA4EF18F17B4FB619EA93DEF7939A33239E08@eusaamb107.ericsson.se>
Accept-Language: en-US
Content-Language: en-US
x-originating-ip: []
Content-Type: multipart/alternative; boundary="_000_ABCAA4EF18F17B4FB619EA93DEF7939A33239E08eusaamb107erics_"
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrCLMWRmVeSWpSXmKPExsUyuXRPlO7F96GhBi0bTSxmX13IaHH11WcW ByaPJUt+Mnl8ufyZLYApissmJTUnsyy1SN8ugSuj5eYWxoJ7bhX/v+xia2Dcb9vFyMEhIWAi 8fKyXBcjJ5ApJnHh3nq2LkYuDiGBo4wSd2ctZQJJCAksZ5R4e48PxGYTsJDY/vs5K0iRiMAq RokLqw6wgySEBYIkuqbPYwaxRQTCJa5Ob2SHsPUkXq78xgJiswioSvzvfQRm8wr4Suw/28EI YjMCbf5+ag3YMmYBcYlbT+YzQVwkILFkz3lmCFtU4uXjf6wQtpLEnNfXmCHq8yUm9kDU8AoI Spyc+YRlAqPQLCSjZiEpm4WkDCKuI7Fg9yc2CFtbYtnC18ww9pkDj5mQxRcwsq9i5CgtTi3L TTcy3MQIjIZjEmyOOxgXfLI8xCjAwajEw7vgUUioEGtiWXFl7iFGaQ4WJXHei6pAIYH0xJLU 7NTUgtSi+KLSnNTiQ4xMHJxSDYxFT5R2ePVPfbfKQOr38yfbGW5oHXjf7rTEPmFfSfW1/OLc v7ybP7R+Wv4ztn5Dd7D/mrfT+PJu7soSihOS3/44bVabd/KTKQ/ub17GkfWkdWGgzvOItR8K GM1fnrm99VNZ3u6etVvdskyDuSYV6/47vZ5t3QzVeY2tjKlx1tOi6oTjVXaqLP+ixFKckWio xVxUnAgA5RkJz2cCAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/gen-art/_JKV--7GDH83YrI9pyKuVYCg1ck>
Subject: [Gen-art] Gen-ART Last Call review of draft-ietf-rtcweb-stun-consent-freshness-13
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 May 2015 20:17:44 -0000

I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq.

Please resolve these comments along with any other Last Call comments you may receive.

Document: draft-ietf-rtcweb-stun-consent-freshness-13
Reviewer: Meral Shirazipour
Review Date: 2015-05-15
IETF LC End Date:  2015-05-15
IESG Telechat date: NA

This draft is ready to be published as Standards Track RFC but I have some comments .

Major issues:

Minor issues:

Nits/editorial comments:

-The abstract lacks context, please consider adding some more text. A suggestion: repeat the first sentence from the intro in the abstract:
"To prevent attacks on peers, endpoints have to ensure the remote peer is willing to receive traffic."

-[Page 2] Intro: It was not clear if this document is specific to webRTC implementations. Is there any limitation to only use for webRTC? Maybe a sentence in the intro could clarify if there is or there is not such limitation.

-[Page 2] Intro, it would be good if the intro section could give a good example (use case, application) of when a receiving end would revoke the consent during the session.(why closing the session is not enough)

-[Page 3], Section2, "Transport Address" definition. It would be good to clarify this wrt 5-tuple. The two terms are used interchangeably, yet Transport address carries only destination IP protocol port, not the sender's (as carried in 5-tuple).
e.g. [Page 4]:"....the remote peer's transport address, the endpoint MUST cease transmission on that 5-tuple."

-[Page 4] "Initial consent to send traffic is obtained using ICE.  Consent expires after 30 seconds."
Is this value specified by [RFC6062] or this document? not clear.

-[Page 4-5]Section 4.1 addresses security issues. Section 8 adds additional content on security. It would be best to consolidate or at least have Section 8 point back to 4.1.


-[Page 5], "can not cause"--->"cannot cause"
-[Page 6], "each others keys"--->"each other's keys"
-[Page 7], typo "through review"--->"thorough review"
-SRTCP,DTLs, etc. please spell out acronyms at first use.

Best Regards,
Meral Shirazipour