Re: [MMUSIC] Secdir last call review of draft-ietf-mmusic-dtls-sdp-22

Christer Holmberg <christer.holmberg@ericsson.com> Thu, 06 April 2017 18:37 UTC

Return-Path: <christer.holmberg@ericsson.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 38B2E12741D; Thu, 6 Apr 2017 11:37:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.22
X-Spam-Level:
X-Spam-Status: No, score=-4.22 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hLeYD19iKbOu; Thu, 6 Apr 2017 11:37:07 -0700 (PDT)
Received: from sessmg23.ericsson.net (sessmg23.ericsson.net [193.180.251.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 86DE2127775; Thu, 6 Apr 2017 11:37:06 -0700 (PDT)
X-AuditID: c1b4fb2d-dadfe700000033e1-4c-58e68ace1958
Received: from ESESSHC024.ericsson.se (Unknown_Domain [153.88.183.90]) by (Symantec Mail Security) with SMTP id F4.C3.13281.ECA86E85; Thu, 6 Apr 2017 20:37:04 +0200 (CEST)
Received: from ESESSMB102.ericsson.se ([169.254.2.218]) by ESESSHC024.ericsson.se ([153.88.183.90]) with mapi id 14.03.0339.000; Thu, 6 Apr 2017 20:37:02 +0200
From: Christer Holmberg <christer.holmberg@ericsson.com>
To: Rich Salz <rsalz@akamai.com>, "secdir@ietf.org" <secdir@ietf.org>
CC: "draft-ietf-mmusic-dtls-sdp.all@ietf.org" <draft-ietf-mmusic-dtls-sdp.all@ietf.org>, "ietf@ietf.org" <ietf@ietf.org>, "mmusic@ietf.org" <mmusic@ietf.org>
Thread-Topic: Secdir last call review of draft-ietf-mmusic-dtls-sdp-22
Thread-Index: AQHSrvc7Q+l4Ggm5cUSsh7p7Glw+qqG4q/Pg
Date: Thu, 06 Apr 2017 18:37:32 +0000
Message-ID: <7594FB04B1934943A5C02806D1A2204B4CB51809@ESESSMB102.ericsson.se>
References: <149149800009.21962.16244679330016077024@ietfa.amsl.com>
In-Reply-To: <149149800009.21962.16244679330016077024@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [153.88.183.149]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFupkkeLIzCtJLcpLzFFi42KZGbE9SvdC17MIg2NtWhY77u5gs3i2cT6L xdTlj1ks/m/pZLH4sPAhiwOrx+QjC5g9liz5yRTAFMVlk5Kak1mWWqRvl8CVcfbfBJaCV0IV 525MZ25gXCPUxcjJISFgItHQ/Zili5GLQ0hgPaPE+mtH2SCcxYwSB16/Ye1i5OBgE7CQ6P6n DdIgIuAqsa33MzNIDbPAQkaJ72c/MYIkhIESk08eYIQocpNY8eAkG4RtJLH08ipmEJtFQEVi z+yHzCAzeQV8JX5OB5spJOAi8f9uHyuIzQk0prd9B5jNKCAm8f3UGiYQm1lAXOLWk/lMEEcL SCzZc54ZwhaVePn4HyuErSSx9vB2FpDxzAKaEut36UO0KkpM6X7IDmLzCghKnJz5hGUCo+gs JFNnIXTMQtIxC0nHAkaWVYyixanFxbnpRsZ6qUWZycXF+Xl6eaklmxiBEXRwy2/dHYyrXzse YhTgYFTi4U348SRCiDWxrLgy9xCjBAezkgiv+nugEG9KYmVValF+fFFpTmrxIUZpDhYlcV6H fRcihATSE0tSs1NTC1KLYLJMHJxSDYzafiEL/xjv2ey6MOeOtVybC8OW1eWnHzvdZj9+++zs G7M2x+xcYnMoui/zvUKcyMsX6455fb6n7z6nwDn/0JHv9r3/Hdjq/1248K9l8up625nFak2b 4w6E6Kmc1ubfayO6Zcuiee7yq4xCV82Xivcq+n06VL3U6M1TUaMFLqbSey6+7fedNrlSiaU4 I9FQi7moOBEAilxX65wCAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/mmusic/N66JqtVVQV1nlYFZAUJRfXDwkFg>
Subject: Re: [MMUSIC] Secdir last call review of draft-ietf-mmusic-dtls-sdp-22
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Apr 2017 18:37:09 -0000

Hi Rich,

Thanks for your review!

Note that, based on discussions in Chicago, the draft will be extended to also cover TLS associations. So, it may end up on your table again at some point :)

Never the less, I will reply to your comments, because some of them are not related to the change.

>Reviewer: Rich Salz
>Review result: Has Nits
>
>The term "ufrag" should be explained, or at least have a reference on its first use.  It seems important :)

I will add a reference to draft-5245bis.

>I think the "fingerprint" reference should be moved up to the bullet list in section 4, from the bullet list in 5.1

I am not sure. The bullet list in section 4 talks about the fingerprint in general, while the bullet list in 5.1 talks about the fingerprint attribute.

>Sec 4 uses the term "cryptographic random function" which is not a common security term.  (See
>https://en.wikipedia.org/wiki/Cryptographically_secure_pseudorandom_number_generator)
>I would just say "strong random function"; it's the number of random bits that counts.  Or use CSPRNG as the term.

I will use "strong random function".

>In Sec 9, it seems like quoting all the old text is way too verbose. 
>I would just say "replace with the following NEW TEXT"
>If it's not replacing an entire section, then say "the nnn paragraphs starting with xxxxx" or similar construct.

This comes up everything a section is updated. Some people only want to updated parts, while others want the whole updated section - no matter how much or little has been updated. So, I'd like to keep it as it is.

Note, however, that based on the gen-art review I will place the updates of each individual section in a separate sub section of the draft.

Regards,

Christer