Re: [Jmap] [Gen-art] Genart last call review of draft-ietf-jmap-websocket-04

Alissa Cooper <alissa@cooperw.in> Mon, 06 January 2020 18:51 UTC

Return-Path: <alissa@cooperw.in>
X-Original-To: jmap@ietfa.amsl.com
Delivered-To: jmap@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9AC90120077; Mon, 6 Jan 2020 10:51:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.72
X-Spam-Level:
X-Spam-Status: No, score=-2.72 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cooperw.in header.b=ciwZe8ee; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=DdR41kRm
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ox9CqWQY_WlC; Mon, 6 Jan 2020 10:51:10 -0800 (PST)
Received: from out2-smtp.messagingengine.com (out2-smtp.messagingengine.com [66.111.4.26]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 24FE9120105; Mon, 6 Jan 2020 10:51:09 -0800 (PST)
Received: from compute7.internal (compute7.nyi.internal [10.202.2.47]) by mailout.nyi.internal (Postfix) with ESMTP id 5623E217FC; Mon, 6 Jan 2020 13:51:08 -0500 (EST)
Received: from mailfrontend1 ([10.202.2.162]) by compute7.internal (MEProxy); Mon, 06 Jan 2020 13:51:08 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cooperw.in; h= content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; s=fm2; bh=3 p3aln5HIcrX/YqACNAwdPyU79NHMggopxRKBsU6CbA=; b=ciwZe8ee/2OmGc8TX KjJkPECOLsxxR6inA6tfDhZQZoc4gPXOH1+DMTNGQsKLQCyPYBPBXIfXNoyjXCxD s9xEFR6yH1fCQFeDIIfI2XNQrKVB+xrcxu/4ytuklWv4R94ZiBZrcjseP3202FBB EDpS/bYFvV13k12UisUiT2VWh+ZEPeTTChznyY6TtVyMiUB5uz5K9GElVd3hGzse rUcRkauryFb0LLlMIPDBEVLHIjWHXPveo3QgFmoXuUOVhkUUDpmCSIcKYtazhskD Cb8k57dOZlBuP4TXnNsptUJjiDV24XKms4K7Qncf9wSuchKfDkHUyCRhQdZQq7xM /y3Uw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; bh=3p3aln5HIcrX/YqACNAwdPyU79NHMggopxRKBsU6C bA=; b=DdR41kRmyJZPLgolIpQI6wEU9qWj6vlEJ+XFPFYix8sm7T7qMIY8ZPdQI g1f69U9QGhIv9o+N/tSuygxgtBjl8nN7B/gsU5KSWARZowboyX9nB4Smpazeb2rI nzLYezc6gRklUUe5yb1slQNjiNCfDE5GNxFki5S5fMuC9PkMJTRrRvB81VlHy+aM ArhSJTjDcMbzqfdT3u7GX4bO251P7HAvOWZA1cDnUGv0mcHOG+6nQzDAIBjZMSHu 26jRc7XZYC4AzYjRgjrgiGefqruD6qGy5lIDiOfHazpSFZv7dFkv1tPYOAPw0EWP StzgMRgz0jJnkEtpgc24i0AuHeZLQ==
X-ME-Sender: <xms:nIETXmV3QIdjPt-b9jKBAU5u58uGcgswcYsWo2_D5NyMvlaYihiKAw>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedufedrvdehtddguddukecutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfgh necuuegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmd enucfjughrpegtggfuhfgjfffgkfhfvffosehtqhhmtdhhtddvnecuhfhrohhmpeetlhhi shhsrgcuvehoohhpvghruceorghlihhsshgrsegtohhophgvrhifrdhinheqnecuffhomh grihhnpehivghtfhdrohhrghdphhhtthhprhgvqhhuvghsthhshhgrshhvvghrhihlohif uggvphhlohihmhgvnhhtrdhishenucfkphepudejfedrfeekrdduudejrdekvdenucfrrg hrrghmpehmrghilhhfrhhomheprghlihhsshgrsegtohhophgvrhifrdhinhenucevlhhu shhtvghrufhiiigvpedt
X-ME-Proxy: <xmx:nIETXpoqL-lesk_TgIGW4utjMa5jvAUJvqTxn86smduQOI3z-FQJng> <xmx:nIETXiGhHYUdWh-UbdpaJL4Cn48_UTngJCOTIbWktmbbfuBhBQt1xw> <xmx:nIETXjv12z77hdSOn0hmoGCGwnxQlRzUsSvIX06iUSIJjzPw71iLaA> <xmx:nIETXk7chviYko8z2KufVLHWOBlVu-w5O0oTY__1_KlB_kaTM_MQXg>
Received: from rtp-alcoop-nitro2.cisco.com (unknown [173.38.117.82]) by mail.messagingengine.com (Postfix) with ESMTPA id 99B8480068; Mon, 6 Jan 2020 13:51:07 -0500 (EST)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
From: Alissa Cooper <alissa@cooperw.in>
In-Reply-To: <157601705841.9885.14627802012368211966@ietfa.amsl.com>
Date: Mon, 06 Jan 2020 13:51:06 -0500
Cc: gen-art@ietf.org, last-call@ietf.org, draft-ietf-jmap-websocket.all@ietf.org, jmap@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <2AD30F37-FDCD-470F-9FA2-36A1788E4D67@cooperw.in>
References: <157601705841.9885.14627802012368211966@ietfa.amsl.com>
To: Linda Dunbar <linda.dunbar@futurewei.com>
X-Mailer: Apple Mail (2.3445.9.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/jmap/2wRHOTvVapQ3IYdk2LtC-OdrSkA>
Subject: Re: [Jmap] [Gen-art] Genart last call review of draft-ietf-jmap-websocket-04
X-BeenThere: jmap@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: JSON Message Access Protocol <jmap.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jmap>, <mailto:jmap-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jmap/>
List-Post: <mailto:jmap@ietf.org>
List-Help: <mailto:jmap-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jmap>, <mailto:jmap-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Jan 2020 18:51:13 -0000

Linda, thanks for your review. I asked a question in my DISCUSS ballot related to your question about MITM (regarding transport confidentiality, not uses of JMAP beyond those specified for the WebSocket binding, which I think is clear).

Alissa

> On Dec 10, 2019, at 5:30 PM, Linda Dunbar via Datatracker <noreply@ietf.org> wrote:
> 
> Reviewer: Linda Dunbar
> Review result: Ready with Nits
> 
> I am the assigned Gen-ART reviewer for this draft. The General Area
> Review Team (Gen-ART) reviews all IETF documents being processed
> by the IESG for the IETF Chair.  Please treat these comments just
> like any other last call comments.
> 
> For more information, please see the FAQ at
> 
> <https://trac.ietf.org/trac/gen/wiki/GenArtfaq>.
> 
> Document: draft-ietf-jmap-websocket-04
> Reviewer: Linda Dunbar
> Review Date: 2019-12-10
> IETF LC End Date: 2019-12-19
> IESG Telechat date: Not scheduled for a telechat
> 
> Summary:  the document describes binding JSON Meta Application Protocol (JMAP)
> over a WebSocket Transport Layer (instead the current HTTP layer)
> 
> The document is written very clear. I think it is ready with a few questions.
> 
> 1. The current practice of binding JMAP over HTTP requires authentication for
> every request, vs. over WebSocket Transport only requires authentication at the
> initial OPEN step. What if there is Man in the Middle attack after the initial
> OPEN?
> 
> 2. In the Introduction you stated that compression for HTTP requests has very
> low deployment. Is it because HTTP request only has very small packet size,
> therefore with very little benefit of compression?
> 
> Major issues:
> 
> Minor issues:
> 
> Nits/editorial comments:
> 
> Best Regards,
> Linda Dunbar
> 
> _______________________________________________
> Gen-art mailing list
> Gen-art@ietf.org
> https://www.ietf.org/mailman/listinfo/gen-art