Re: Opsdir telechat review of draft-gutmann-scep-10

Peter Gutmann <pgut001@cs.auckland.ac.nz> Mon, 07 May 2018 11:39 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1EE4512D777; Mon, 7 May 2018 04:39:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=auckland.ac.nz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9f_ySeBR2p0z; Mon, 7 May 2018 04:39:14 -0700 (PDT)
Received: from mx4-int.auckland.ac.nz (mx4-int.auckland.ac.nz [130.216.125.246]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AFD661200C1; Mon, 7 May 2018 04:39:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=@auckland.ac.nz; q=dns/txt; s=mail; t=1525693154; x=1557229154; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=ZVfcTs/5JAG3YUN+yDRBsivIHDmo6shBg7iEO+QAiZo=; b=CSfLELnELLL7d+4CTNZ5G45JQF1jXWi5C7mofGw5FigF8RPxRUVTSKKH GWmVPPMHcgUyTMr4/6/za6ef6d59DiRrlAmwW6rITalO+sdsP6p0ALsiQ wKrG6/W3uSEerZVbPXLPrvxar4NUPHr/geUOP2jmjWSyBC1XcXWIuujoW HMTMHPedrfmQoAR9hIqV4xYnW6DwpBjVwKKktvf5WbBa1M4A0s/dXOJE7 a83kxcE8WgHY4iIptzxfblDOSBhM/r9WJqn66hpKMh9NQdcBX/mHA0fs7 JskjFUyyy7t50gcYr3NDW38XqmXsreky2KPCPfx5bb5FSpgszfT98S0+3 w==;
X-IronPort-AV: E=Sophos;i="5.49,373,1520852400"; d="scan'208";a="9783801"
X-Ironport-HAT: MAIL-SERVERS - $RELAYED
X-Ironport-Source: 10.6.2.3 - Outgoing - Outgoing
Received: from exchangemx.uoa.auckland.ac.nz (HELO uxcn13-ogg-b.UoA.auckland.ac.nz) ([10.6.2.3]) by mx4-int.auckland.ac.nz with ESMTP/TLS/AES256-SHA; 07 May 2018 23:39:10 +1200
Received: from uxcn13-tdc-d.UoA.auckland.ac.nz (10.6.3.5) by uxcn13-ogg-b.UoA.auckland.ac.nz (10.6.2.3) with Microsoft SMTP Server (TLS) id 15.0.1263.5; Mon, 7 May 2018 23:39:10 +1200
Received: from uxcn13-tdc-d.UoA.auckland.ac.nz ([fe80::9f5:baf3:43e7:a6e6]) by uxcn13-tdc-d.UoA.auckland.ac.nz ([fe80::9f5:baf3:43e7:a6e6%14]) with mapi id 15.00.1263.000; Mon, 7 May 2018 23:39:10 +1200
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Susan Hares <shares@ndzh.com>, "ops-dir@ietf.org" <ops-dir@ietf.org>
CC: "draft-gutmann-scep.all@ietf.org" <draft-gutmann-scep.all@ietf.org>, "ietf@ietf.org" <ietf@ietf.org>
Subject: Re: Opsdir telechat review of draft-gutmann-scep-10
Thread-Topic: Opsdir telechat review of draft-gutmann-scep-10
Thread-Index: AQHT3UlWho4NBvwcbEiDcUmHRdpxjaQkNUps
Date: Mon, 07 May 2018 11:39:10 +0000
Message-ID: <1525693149502.33199@cs.auckland.ac.nz>
References: <152473851310.23039.16168330403404093767@ietfa.amsl.com>
In-Reply-To: <152473851310.23039.16168330403404093767@ietfa.amsl.com>
Accept-Language: en-NZ, en-GB, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [130.216.158.4]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/s-Cyqr-VOj3rOZVwWF1gvX8_TqA>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 May 2018 11:39:17 -0000

Apologies for the slow reply, I've been buried in work recently:

>p. 19, section 3.3.1, British spelling of authorization is used
>(authorisation). RFC editor may want to change or author may want to change
>to US spelling.

The author speaks British English :-).  As I told a US Customs person some
years ago, "madam, I speak the Queen's English".  I'm not sure they were
impressed.

Peter.

________________________________________
From: Susan Hares <shares@ndzh.com>
Sent: Thursday, 26 April 2018 22:28
To: ops-dir@ietf.org
Cc: draft-gutmann-scep.all@ietf.org; ietf@ietf.org
Subject: Opsdir telechat review of draft-gutmann-scep-10

Reviewer: Susan Hares
Review result: Ready

caveat:  I am not a security expert famliy with the deployment of the SCEP
protocol. If an operational experience with this protocol is required for this
review, I suggest you obtain a secondary review.

General comments: The document summarizes in a readable fashion all the issues
I could image regarding this protocol's deployment issues.  Issues of scale and
security have been examined.

Editorial:
p. 19, section 3.3.1, British spelling of authorization is used
(authorisation). RFC editor may want to change or author may want to change to
US spelling.

p. 26 - I appreciate the use of  non-idempotent and idempotent in this section.
 I hope this is normal language for the security area.