[httpapi] Secdir telechat review of draft-ietf-httpapi-api-catalog-06

Joey Salazar via Datatracker <noreply@ietf.org> Wed, 04 December 2024 17:59 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: httpapi@ietf.org
Delivered-To: httpapi@ietfa.amsl.com
Received: from [10.244.8.175] (unknown [104.131.183.230]) by ietfa.amsl.com (Postfix) with ESMTP id BF1A6C14F5FF; Wed, 4 Dec 2024 09:59:05 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Joey Salazar via Datatracker <noreply@ietf.org>
To: secdir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.28.2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <173333514542.1849104.6346640241718992848@dt-datatracker-5679c9c6d-qbvvv>
Date: Wed, 04 Dec 2024 09:59:05 -0800
Message-ID-Hash: HY5BESBH5PPDBTERS6GNGZQBKSYEGM4G
X-Message-ID-Hash: HY5BESBH5PPDBTERS6GNGZQBKSYEGM4G
X-MailFrom: noreply@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-httpapi-api-catalog.all@ietf.org, httpapi@ietf.org, last-call@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: Joey Salazar <joeygsal@gmail.com>
Subject: [httpapi] Secdir telechat review of draft-ietf-httpapi-api-catalog-06
List-Id: Building Blocks for HTTP APIs <httpapi.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/httpapi/lJl68gHQBhbVHbF0kyaCKg-_9tA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/httpapi>
List-Help: <mailto:httpapi-request@ietf.org?subject=help>
List-Owner: <mailto:httpapi-owner@ietf.org>
List-Post: <mailto:httpapi@ietf.org>
List-Subscribe: <mailto:httpapi-join@ietf.org>
List-Unsubscribe: <mailto:httpapi-leave@ietf.org>

Reviewer: Joey Salazar
Review result: Ready

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written primarily for the benefit of the
security area directors.  Document editors and WG chairs should treat
these comments just like any other last call comments.

Please note that I previously reviewed version 05 of this draft and at that
time stated that the document was "Ready with Issues".

I am therefore only reviewing the differences between version 05 and current
version (06) and, due to time constrains for the upcoming Telechat, only
those differences pertaining to my previous review.

The summary of the review is: Ready

Major Concerns: None
The major concern highlighted in the previous review has been addressed with
the text added to the Security Considerations in section 8. The new text covers
the cases mentioned in my previous review and recommended references.

Minor Concerns: None

Nits:

All nits have been addressed except the double spacing between the end of a
sentence and the beginning of the next sentence in the same paragraph, which
can be interpreted as a styling choice. No new nits to remark on.

Thank you for the quick update and incorporation of feedback.