[Last-Call] Secdir last call review of draft-murchison-rfc8536bis-12

Vincent Roca via Datatracker <noreply@ietf.org> Tue, 09 April 2024 14:02 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: last-call@ietf.org
Delivered-To: last-call@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 64421C14F60D; Tue, 9 Apr 2024 07:02:46 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Vincent Roca via Datatracker <noreply@ietf.org>
To: secdir@ietf.org
Cc: draft-murchison-rfc8536bis.all@ietf.org, last-call@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.9.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <171267136639.39452.923786431000419885@ietfa.amsl.com>
Reply-To: Vincent Roca <vincent.roca@inria.fr>
Date: Tue, 09 Apr 2024 07:02:46 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/last-call/ykmQRjkW-hgHiK_Uy_iTPx2XU8A>
Subject: [Last-Call] Secdir last call review of draft-murchison-rfc8536bis-12
X-BeenThere: last-call@ietf.org
X-Mailman-Version: 2.1.39
List-Id: IETF Last Calls <last-call.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/last-call>, <mailto:last-call-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/last-call/>
List-Post: <mailto:last-call@ietf.org>
List-Help: <mailto:last-call-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/last-call>, <mailto:last-call-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Apr 2024 14:02:46 -0000

Reviewer: Vincent Roca
Review result: Ready

Hello,

I have reviewed this document as part of the security directorate’s ongoing
effort to review all IETF documents being processed by the IESG. These
comments were written primarily for the benefit of the security area
directors. Document editors and WG chairs should treat these comments just
like any other last call comments.

Summary: Ready

I just have a minor comment regarding Section 6 "Security Considerations" and 7
"Privacy Considerations". The current draft briefly mentions RFC 7808 whereas
this RFC has very detailed security and privacy sections and is a MUST READ. I
suggest the authors refer to RFC 7808 in both sections for further security or
privacy information in a convincing manner.

Regards,   Vincent