[netconf] Secdir last call review of draft-ietf-netconf-http-client-server-16

Shivan Sahib via Datatracker <noreply@ietf.org> Sat, 10 February 2024 02:58 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: netconf@ietf.org
Delivered-To: netconf@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id DB671C1519B1; Fri, 9 Feb 2024 18:58:51 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Shivan Sahib via Datatracker <noreply@ietf.org>
To: secdir@ietf.org
Cc: draft-ietf-netconf-http-client-server.all@ietf.org, last-call@ietf.org, netconf@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.5.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <170753393187.36817.12725850532997691597@ietfa.amsl.com>
Reply-To: Shivan Sahib <shivankaulsahib@gmail.com>
Date: Fri, 09 Feb 2024 18:58:51 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/hORVyZOhQnRPEpTpk4Y-LxGewjs>
Subject: [netconf] Secdir last call review of draft-ietf-netconf-http-client-server-16
X-BeenThere: netconf@ietf.org
X-Mailman-Version: 2.1.39
List-Id: NETCONF WG list <netconf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netconf>, <mailto:netconf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf/>
List-Post: <mailto:netconf@ietf.org>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 10 Feb 2024 02:58:52 -0000

Reviewer: Shivan Sahib
Review result: Has Nits

It looks like the document previously got review from HTTP WG, and generally
looks well thought out. However, I'm not sure why only TCP and TLS are
discussed in
https://datatracker.ietf.org/doc/html/draft-ietf-netconf-http-client-server-16#section-2.1.2.2.
Is the intention that network protocols like QUIC can be "augmented" in? I
suspected that, but in that case, it should be mentioned the same way Basic
auth is explicitly mentioned to be only one of the ways auth can happen with a
MAY for other schemes:
https://datatracker.ietf.org/doc/html/draft-ietf-netconf-http-client-server-16#section-2.1.2.1-4.4