[Gen-art] Re: Gen-art review of draft-ietf-radext-rfc4590bis-01.txt

David Williams <dwilli@cisco.com> Wed, 23 May 2007 21:10 UTC

Return-path: <gen-art-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1Hqy6D-0002kq-Oa; Wed, 23 May 2007 17:10:25 -0400
Received: from gen-art by megatron.ietf.org with local (Exim 4.43) id 1HqwwG-0005rl-C6 for gen-art-confirm+ok@megatron.ietf.org; Wed, 23 May 2007 15:56:04 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HqwwG-0005rY-29 for gen-art@ietf.org; Wed, 23 May 2007 15:56:04 -0400
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HqwwE-0001xR-M6 for gen-art@ietf.org; Wed, 23 May 2007 15:56:04 -0400
Received: from sj-dkim-1.cisco.com ([171.71.179.21]) by sj-iport-3.cisco.com with ESMTP; 23 May 2007 12:56:02 -0700
X-IronPort-AV: i="4.14,571,1170662400"; d="scan'208"; a="488015402:sNHT457064168"
Received: from sj-core-2.cisco.com (sj-core-2.cisco.com [171.71.177.254]) by sj-dkim-1.cisco.com (8.12.11/8.12.11) with ESMTP id l4NJu1nq018207; Wed, 23 May 2007 12:56:01 -0700
Received: from xbh-sjc-211.amer.cisco.com (xbh-sjc-211.cisco.com [171.70.151.144]) by sj-core-2.cisco.com (8.12.10/8.12.6) with ESMTP id l4NJtdaQ025950; Wed, 23 May 2007 19:55:39 GMT
Received: from xfe-sjc-212.amer.cisco.com ([171.70.151.187]) by xbh-sjc-211.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.1830); Wed, 23 May 2007 12:55:31 -0700
Received: from dwilli-wxp01.amer.cisco.com ([64.101.175.210]) by xfe-sjc-212.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.1830); Wed, 23 May 2007 12:55:31 -0700
Date: Wed, 23 May 2007 15:55:10 -0400
From: David Williams <dwilli@cisco.com>
To: Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com>
In-Reply-To: <4652CC8F.2030208@ericsson.com>
Message-ID: <Pine.WNT.4.64.0705221432270.4640@dwilli-wxp01.amer.cisco.com>
References: <4652CC8F.2030208@ericsson.com>
X-Warning: UNAuthenticated Sender
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"; format="flowed"
X-OriginalArrivalTime: 23 May 2007 19:55:31.0283 (UTC) FILETIME=[5185AA30:01C79D74]
DKIM-Signature: v=0.5; a=rsa-sha256; q=dns/txt; l=1676; t=1179950161; x=1180814161; c=relaxed/simple; s=sjdkim1004; h=Content-Type:From:Subject:Content-Transfer-Encoding:MIME-Version; d=cisco.com; i=dwilli@cisco.com; z=From:=20David=20Williams=20<dwilli@cisco.com> |Subject:=20Re=3A=20Gen-art=20review=20of=20draft-ietf-radext-rfc4590bis- 01.txt |Sender:=20; bh=NOlejind++y9yFzMMu1XUewknV1vbRl5SMjAEwVE8bE=; b=IKn3gcupmw+QXdCyk0sqilryt/Oqi2E8bqKQ2/ec4Sn87F417r7FoDiO/xFaZEkOT4S+fYnI ppbQGISvSgHw73zVW9S37OI6bszk8F0sd7tdQb9sT81J5oyTPMlcjpOL86f0+aNIIociOACyxb a6INeiMUPmq8WcTRBPOJfk2Qg=;
Authentication-Results: sj-dkim-1; header.From=dwilli@cisco.com; dkim=pass ( sig from cisco.com/sjdkim1004 verified; );
X-Spam-Score: 0.0 (/)
X-Scan-Signature: f4c2cf0bccc868e4cc88dace71fb3f44
X-Mailman-Approved-At: Wed, 23 May 2007 17:10:24 -0400
Cc: dromasca@avaya.com, Bernard_Aboba@hotmail.com, rbonica@juniper.net, dscreat@dscreat.com, baruch@kayote.com, gen-art@ietf.org, d.b.nelson@comcast.net, beckw@t-systems.com, david@kayote.com
Subject: [Gen-art] Re: Gen-art review of draft-ietf-radext-rfc4590bis-01.txt
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/gen-art>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
Errors-To: gen-art-bounces@ietf.org

On Tue, 22 May 2007, 1:57pm, Gonzalo Camarillo wRote:

> Hi,
>
> I have been selected as the General Area Review Team (Gen-ART)
> reviewer for this draft (for background on Gen-ART, please see
> http://www.alvestrand.no/ietf/gen/art/gen-art-FAQ.html).
>
> Please resolve these comments along with any other Last Call comments
> you may receive.
>
>
> Draft: draft-ietf-radext-rfc4590bis-01.txt
> Reviewer: Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com>
> Review Date: 22 May 2006
>
> Summary:
>
> This draft is ready for publication as a PS RFC.
>
>
> Comments:
>
> RFC 3579, which appears in the References, is an Informational RFC
> (i.e., it is a down reference).

Meaning this should appear in section 9.2 instead of 9.1?  Or that the 
text should some somehow refer back to some standard reference versus 
rfc3579.  Sorry for my ignorant question.


>
> Section 2.1 explains that information sent over a TLS connection to the
> RADIUS client may be sent in cleartext to the RADIUS server, but does
> not give any recommendation on what to do in that case. A further
> explanation or a recommendation would be useful.

This is discussed more in Section 8.2.   What is the best way to approach 
this, prehaps by adding a sentence to the end of the paragraph like:

"2.1 RADIUS Client Behavior

The attributes described ..... result in information 
intentionally protected by HTTP-style clients being sent in the clear 
during RADIUS exchange.  Ways to mitigate this exposure are discussed in 
section 8.2"

Or is it prefered to summarize the problem in section 2.1.

thanks,
-david

>
>
> Thanks,
>
> Gonzalo
>


_______________________________________________
Gen-art mailing list
Gen-art@ietf.org
https://www1.ietf.org/mailman/listinfo/gen-art