[Lwip] Secdir last call review of draft-ietf-lwig-curve-representations-12

Russ Housley via Datatracker <noreply@ietf.org> Thu, 27 August 2020 19:35 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: lwip@ietf.org
Delivered-To: lwip@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 173F53A1251; Thu, 27 Aug 2020 12:35:06 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Russ Housley via Datatracker <noreply@ietf.org>
To: secdir@ietf.org
Cc: last-call@ietf.org, lwip@ietf.org, draft-ietf-lwig-curve-representations.all@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 7.14.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <159855690603.24456.6910199800419438393@ietfa.amsl.com>
Reply-To: Russ Housley <housley@vigilsec.com>
Date: Thu, 27 Aug 2020 12:35:06 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/lwip/MOkTFhQyh-RNrTI-guN0Vlq2Wdc>
Subject: [Lwip] Secdir last call review of draft-ietf-lwig-curve-representations-12
X-BeenThere: lwip@ietf.org
X-Mailman-Version: 2.1.29
List-Id: "Lightweight IP stack. Official mailing list for IETF LWIG Working Group." <lwip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lwip>, <mailto:lwip-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lwip/>
List-Post: <mailto:lwip@ietf.org>
List-Help: <mailto:lwip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lwip>, <mailto:lwip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 Aug 2020 19:35:06 -0000

Reviewer: Russ Housley
Review result: Ready

I reviewed this document as part of the Security Directorate's ongoing
effort to review all IETF documents being processed by the IESG.  These
comments were written primarily for the benefit of the Security Area
Directors.  Document authors, document editors, and WG chairs should
treat these comments just like any other IETF Last Call comments.

Document: draft-ietf-lwig-curve-representations-12
Reviewer: Russ Housley
Review Date: 2020-08-27
IETF LC End Date: 2020-09-08
IESG Telechat date: unknown

Thank you for addressing my earlier comments on -08.

Summary: Ready


Major Concerns:  None


Minor Concerns:  None


Nits:

The Introduction talks about the traditional "short" Weierstrass curve
model, and then most everywhere else talks about short-Weierstrass form.
Can one phrase be used throughout?


Question:

Is support for these curves with in PKIX certificates (see RFC 5280
and RFC 5480) and CMS (see RFC 5652 and RFC 5753) as simple as
assigning an object identifier for the two named curves?  If so, can
Section 10 be expanded to cover these too?