[Last-Call] Secdir telechat review of draft-ietf-httpapi-deprecation-header-08
Robert Sparks via Datatracker <noreply@ietf.org> Fri, 13 September 2024 15:09 UTC
Return-Path: <noreply@ietf.org>
X-Original-To: last-call@ietf.org
Delivered-To: last-call@ietfa.amsl.com
Received: from [10.244.2.118] (unknown [104.131.183.230]) by ietfa.amsl.com (Postfix) with ESMTP id 19C80C14F60B; Fri, 13 Sep 2024 08:09:59 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Robert Sparks via Datatracker <noreply@ietf.org>
To: secdir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.23.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <172624019874.3455295.10932170001108961965@dt-datatracker-68b7b78cf9-q8rsp>
Date: Fri, 13 Sep 2024 08:09:58 -0700
Message-ID-Hash: DG75WWMNPMDNBPFRUYBKKYRVSJP6HNEP
X-Message-ID-Hash: DG75WWMNPMDNBPFRUYBKKYRVSJP6HNEP
X-MailFrom: noreply@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-httpapi-deprecation-header.all@ietf.org, httpapi@ietf.org, last-call@ietf.org
X-Mailman-Version: 3.3.9rc4
Reply-To: Robert Sparks <rjsparks@nostrum.com>
Subject: [Last-Call] Secdir telechat review of draft-ietf-httpapi-deprecation-header-08
List-Id: IETF Last Calls <last-call.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/last-call/5YH0S_Okpj2MbmT5NI36hxlx_BY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/last-call>
List-Help: <mailto:last-call-request@ietf.org?subject=help>
List-Owner: <mailto:last-call-owner@ietf.org>
List-Post: <mailto:last-call@ietf.org>
List-Subscribe: <mailto:last-call-join@ietf.org>
List-Unsubscribe: <mailto:last-call-leave@ietf.org>
Reviewer: Robert Sparks Review result: Has Nits I was also the genart reviewer for this document. See that review at https://datatracker.ietf.org/doc/review-ietf-httpapi-deprecation-header-06-genart-lc-sparks-2024-08-29/. I was hoping another reviewer could make comments about the security aspects of this document, so I didn't emphasize that in my genart review. With the security lens in mind: This document provides a mechanic to transport a date and a pointer to information to the humans, ostensibly the developers, behind appllications using HTTP resources about the deprecation of those resources. The use of HTTP, and HTTPS mitigate risks to the attacks on the date and pointer themselves. There's no behavior specified that insists clients do, or don't do, something different when the deprecation date passes. There is some text that reinforces that this is information from the (operators of the) server (or should that be the administrators of the resources?) and that _servers_ shouldn't act differently, other than providing the information, because they are using the header. I can't think of anything further that could be said about the human use of the information pointed to given what the document specifies. (I've indicated "has nits" as I still think it might be possible to more clearly say "who is this for" in several places.) RjS
- [Last-Call] Secdir telechat review of draft-ietf-… Robert Sparks via Datatracker
- [Last-Call] Re: Secdir telechat review of draft-i… Sanjay Dalal
- [Last-Call] Re: Secdir telechat review of draft-i… Robert Sparks