Re: [Last-Call] [lamps] Genart telechat review of draft-ietf-lamps-cms-update-alg-id-protect-03

Russ Housley <housley@vigilsec.com> Wed, 26 August 2020 16:26 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: last-call@ietfa.amsl.com
Delivered-To: last-call@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 982B83A15FC for <last-call@ietfa.amsl.com>; Wed, 26 Aug 2020 09:26:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6CtgA7QH4NpB for <last-call@ietfa.amsl.com>; Wed, 26 Aug 2020 09:26:55 -0700 (PDT)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A1ACD3A15F5 for <last-call@ietf.org>; Wed, 26 Aug 2020 09:26:55 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 34514300B8D for <last-call@ietf.org>; Wed, 26 Aug 2020 12:21:00 -0400 (EDT)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 0aocjBFGGEPC for <last-call@ietf.org>; Wed, 26 Aug 2020 12:20:58 -0400 (EDT)
Received: from a860b60074bd.fios-router.home (pool-141-156-161-153.washdc.fios.verizon.net [141.156.161.153]) by mail.smeinc.net (Postfix) with ESMTPSA id E587030009B; Wed, 26 Aug 2020 12:20:57 -0400 (EDT)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.15\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <159841625970.23138.505710654934913808@ietfa.amsl.com>
Date: Wed, 26 Aug 2020 12:20:59 -0400
Cc: IETF Gen-ART <gen-art@ietf.org>, LAMPS WG <spasm@ietf.org>, last-call@ietf.org, draft-ietf-lamps-cms-update-alg-id-protect.all@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <2E909C54-1CE1-43B9-BDD3-CEBD7600450F@vigilsec.com>
References: <159841625970.23138.505710654934913808@ietfa.amsl.com>
To: Peter Yee <peter@akayla.com>
X-Mailer: Apple Mail (2.3445.104.15)
Archived-At: <https://mailarchive.ietf.org/arch/msg/last-call/Gy21YcAgxRVAwG5oYk8W14K7_Y8>
Subject: Re: [Last-Call] [lamps] Genart telechat review of draft-ietf-lamps-cms-update-alg-id-protect-03
X-BeenThere: last-call@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF Last Calls <last-call.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/last-call>, <mailto:last-call-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/last-call/>
List-Post: <mailto:last-call@ietf.org>
List-Help: <mailto:last-call-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/last-call>, <mailto:last-call-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Aug 2020 16:26:57 -0000

Peter:

> Nits/editorial comments:
> 
> Page 2, section 1, 2nd paragraph, last sentence: change "associate" to
> "associated".

Done.

> Page 4, 1st NEW block, 4th sentence: insert "the" before "signedAttrs field".

Fixed.

> Page 5, section 3.5, 2nd paragraph, 1st sentence: insert "the" before "same
> digest".

Done.

> Page 5, section 4 title: change "Recommend" to "Recommended" for parallel
> construction with the section 3 title.

Okay, done.

> Page 6, ADD block: delete the first "known".

Based on another comment, I have reworded this to say:

   While there are no known algorithm substitution attacks today,
   the inclusion of the algorithm identifiers used by the originator
   as a signed attribute or an authenticated attribute makes such an
   attack significantly more difficult.

> Page 6, section 6, 3rd paragraph, 5th sentence: change "signalling" to
> "signaling".

Done.

Thanks for the careful review.

Russ