Re: [Gen-art] [lamps] Genart telechat review of draft-ietf-lamps-cms-update-alg-id-protect-03

Russ Housley <housley@vigilsec.com> Wed, 26 August 2020 16:26 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D6F1D3A15F5 for <gen-art@ietfa.amsl.com>; Wed, 26 Aug 2020 09:26:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AEtzTdkWtzya for <gen-art@ietfa.amsl.com>; Wed, 26 Aug 2020 09:26:55 -0700 (PDT)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C0EDA3A15F6 for <gen-art@ietf.org>; Wed, 26 Aug 2020 09:26:55 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 296EC300B8C for <gen-art@ietf.org>; Wed, 26 Aug 2020 12:21:00 -0400 (EDT)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id LdSoB6_cQy33 for <gen-art@ietf.org>; Wed, 26 Aug 2020 12:20:58 -0400 (EDT)
Received: from a860b60074bd.fios-router.home (pool-141-156-161-153.washdc.fios.verizon.net [141.156.161.153]) by mail.smeinc.net (Postfix) with ESMTPSA id E587030009B; Wed, 26 Aug 2020 12:20:57 -0400 (EDT)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.15\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <159841625970.23138.505710654934913808@ietfa.amsl.com>
Date: Wed, 26 Aug 2020 12:20:59 -0400
Cc: IETF Gen-ART <gen-art@ietf.org>, LAMPS WG <spasm@ietf.org>, last-call@ietf.org, draft-ietf-lamps-cms-update-alg-id-protect.all@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <2E909C54-1CE1-43B9-BDD3-CEBD7600450F@vigilsec.com>
References: <159841625970.23138.505710654934913808@ietfa.amsl.com>
To: Peter Yee <peter@akayla.com>
X-Mailer: Apple Mail (2.3445.104.15)
Archived-At: <https://mailarchive.ietf.org/arch/msg/gen-art/boLYyv1RL45CFAlc9GDUsw5z4-o>
Subject: Re: [Gen-art] [lamps] Genart telechat review of draft-ietf-lamps-cms-update-alg-id-protect-03
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Aug 2020 16:26:57 -0000

Peter:

> Nits/editorial comments:
> 
> Page 2, section 1, 2nd paragraph, last sentence: change "associate" to
> "associated".

Done.

> Page 4, 1st NEW block, 4th sentence: insert "the" before "signedAttrs field".

Fixed.

> Page 5, section 3.5, 2nd paragraph, 1st sentence: insert "the" before "same
> digest".

Done.

> Page 5, section 4 title: change "Recommend" to "Recommended" for parallel
> construction with the section 3 title.

Okay, done.

> Page 6, ADD block: delete the first "known".

Based on another comment, I have reworded this to say:

   While there are no known algorithm substitution attacks today,
   the inclusion of the algorithm identifiers used by the originator
   as a signed attribute or an authenticated attribute makes such an
   attack significantly more difficult.

> Page 6, section 6, 3rd paragraph, 5th sentence: change "signalling" to
> "signaling".

Done.

Thanks for the careful review.

Russ