[Last-Call] Artart last call review of draft-ietf-ipsecme-ikev2-auth-announce-06

Marc Blanchet via Datatracker <noreply@ietf.org> Sat, 23 March 2024 03:00 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: last-call@ietf.org
Delivered-To: last-call@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 054ACC151081; Fri, 22 Mar 2024 20:00:10 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Marc Blanchet via Datatracker <noreply@ietf.org>
To: art@ietf.org
Cc: draft-ietf-ipsecme-ikev2-auth-announce.all@ietf.org, ipsec@ietf.org, last-call@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.8.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <171116281000.19763.4229256017849623476@ietfa.amsl.com>
Reply-To: Marc Blanchet <marc.blanchet@viagenie.ca>
Date: Fri, 22 Mar 2024 20:00:10 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/last-call/-_WZIwY_QDEGYNadjljED45Y8yk>
Subject: [Last-Call] Artart last call review of draft-ietf-ipsecme-ikev2-auth-announce-06
X-BeenThere: last-call@ietf.org
X-Mailman-Version: 2.1.39
List-Id: IETF Last Calls <last-call.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/last-call>, <mailto:last-call-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/last-call/>
List-Post: <mailto:last-call@ietf.org>
List-Help: <mailto:last-call-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/last-call>, <mailto:last-call-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 23 Mar 2024 03:00:10 -0000

Reviewer: Marc Blanchet
Review result: Ready with Nits

I'm the assigned ART reviewer for this document. While I'm aware of IPSEC-IKE
and its use, I have no competency in this technology, therefore I have not
verified the substantive protocol specification itself.

Comment 1)
The draft does not specify any fallback procedure or how to handle the
situation when no proper authentication  method can be chosen by one of the
peers. Maybe it is specified elsewhere? Or maybe it is so obvious there is no
point in saying? Or it may be useful to specify some?

Nits:
3.2.2 "If no Certificate Request payload were receives" s/receives/received/ ?