[Ntp] Eric Rescorla's No Objection on draft-ietf-ntp-mac-05: (with COMMENT)

Eric Rescorla <ekr@rtfm.com> Sat, 17 November 2018 22:59 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: ntp@ietf.org
Delivered-To: ntp@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 961D7130DF6; Sat, 17 Nov 2018 14:59:22 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Eric Rescorla <ekr@rtfm.com>
To: The IESG <iesg@ietf.org>
Cc: ntp-chairs@ietf.org, Karen O'Donoghue <odonoghue@isoc.org>, ntp@ietf.org, draft-ietf-ntp-mac@ietf.org, odonoghue@isoc.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.88.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <154249556260.15903.907105541022924420.idtracker@ietfa.amsl.com>
Date: Sat, 17 Nov 2018 14:59:22 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/3SOqCaTdWECVzMS6Lhi6y59EPtg>
X-Mailman-Approved-At: Sat, 17 Nov 2018 20:18:18 -0800
Subject: [Ntp] Eric Rescorla's No Objection on draft-ietf-ntp-mac-05: (with COMMENT)
X-BeenThere: ntp@ietf.org
X-Mailman-Version: 2.1.29
List-Id: <ntp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ntp>, <mailto:ntp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp/>
List-Post: <mailto:ntp@ietf.org>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ntp>, <mailto:ntp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 17 Nov 2018 22:59:23 -0000

Eric Rescorla has entered the following ballot position for
draft-ietf-ntp-mac-05: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-ntp-mac/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Rich version of this review at:
https://mozphab-ietf.devsvcdev.mozaws.net/D3591



COMMENTS
S 3.
>      If authentication is implemented, then AES-CMAC as specified in RFC
>      4493 [RFC4493] SHOULD be computed over all fields in the NTP header,
>      and any extension fields that are present in the NTP packet as
>      described in RFC 5905 [RFC5905].  The MAC key for NTP MUST be at
>      least 128 bits long AES-128 key and the resulting MAC tag MUST be at
>      least 128 bits long as stated in section 2.4 of RFC 4493 [RFC4493].

Is there a way for either of these values to be > 128 bits? If not,
maube just say "must be 128 buts: