[Ntp] WGLC comments on draft-ietf-ntp-using-nts-for-ntp-14

Marcus Dansarie <marcus@dansarie.se> Thu, 15 November 2018 22:00 UTC

Return-Path: <marcus.dansarie.nilsson@gmail.com>
X-Original-To: ntp@ietfa.amsl.com
Delivered-To: ntp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 53527130ECD for <ntp@ietfa.amsl.com>; Thu, 15 Nov 2018 14:00:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.401
X-Spam-Level:
X-Spam-Status: No, score=-1.401 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.25, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id M_mG6uYBst7j for <ntp@ietfa.amsl.com>; Thu, 15 Nov 2018 14:00:37 -0800 (PST)
Received: from mail-lj1-x234.google.com (mail-lj1-x234.google.com [IPv6:2a00:1450:4864:20::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BFC68130EC7 for <ntp@ietf.org>; Thu, 15 Nov 2018 14:00:36 -0800 (PST)
Received: by mail-lj1-x234.google.com with SMTP id x85-v6so18596827ljb.2 for <ntp@ietf.org>; Thu, 15 Nov 2018 14:00:36 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:to:from:subject:openpgp:autocrypt:message-id:date:user-agent :mime-version:content-language:content-transfer-encoding; bh=k1TlwqPPmSuzo2zdyDvu/Lf3DSzdHRqj5C5HNmj4MyI=; b=jT2tkYkYWEkJ/bVvViPnliGCtUG8d//ETPvT0hYIsx9Im3OtOFesrOIfQ3TPUAMxnj UAeYUfZwIi5FEISzsNgAkM2jrcC1+qqOPsrT3Vq67dYpaCcRmyxRXSPvYEIYeVZc2OXn 9c+Xs/q4GWenqSEzLaEkuRDiDE/LFT9phRgvABMdnjDjGHDxUsNr3n2x2C7uf3N8CZc4 ChbwDFheXKOQn5EfCVOPXVbrcv+CEYfulMBQsgCltylUAmz5bMyJ+H0nodeev++di0Ec 64wA/BjMXcJD5YKF+1UYxgfItRh6Z27+2kKskK2b1RsQtQQKCGD5bvJccH4VOBbZHYTg 9JTA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:to:from:subject:openpgp:autocrypt :message-id:date:user-agent:mime-version:content-language :content-transfer-encoding; bh=k1TlwqPPmSuzo2zdyDvu/Lf3DSzdHRqj5C5HNmj4MyI=; b=fg2Spq4Teun+2a0wyakqncWTkY1TMCjH00RTRWv2jGoi2vHN+AXmQvWYsocxk8CYs/ xYzSm2W9ppd4nuYUivEPFPQv4wOzGykwpOHLshKpQ+OFHUpr/bbhQhasS3p7d86HNlJ9 sG0IlR/dx53Yt2NM4uzVd9jEbqyouNmlywWpXa2r/XOxXkNktV1hmvAfauN6ZtMcOU6c bpUyXIb3qcEtpoEufp1sEL4LKIs5j5xxmnDkTXwdENVsPQ3yzdKeGX1M8TCIutmSxlVL EOmCYb/ZGggNoO2gDtAbQtQXzYaEnPU+KM2hDBGTWIeg9B+joZYw9EXrepdoUVJQjJL5 U6ag==
X-Gm-Message-State: AGRZ1gI/9UIQ4fcMfdQc2uc6Hc2a2UUpaWsEQchdfvbKzdok+syJ7oJF ywfDtxvk0g4DEkUky+/hkOJB9QQ3
X-Google-Smtp-Source: AJdET5c2FHEbYNmHFmLLFu03DC1OuZgMLdAbq7a3VEmENFMd7bKLZqsO/cl5gjlh1JhsQ6w2SC1WPQ==
X-Received: by 2002:a2e:197:: with SMTP id f23-v6mr4616720lji.144.1542319234638; Thu, 15 Nov 2018 14:00:34 -0800 (PST)
Received: from [10.0.0.126] ([185.40.184.26]) by smtp.gmail.com with ESMTPSA id j12-v6sm405826ljh.66.2018.11.15.14.00.33 for <ntp@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 15 Nov 2018 14:00:33 -0800 (PST)
Sender: Marcus Dansarie <marcus.dansarie.nilsson@gmail.com>
To: ntp@ietf.org
From: Marcus Dansarie <marcus@dansarie.se>
Openpgp: preference=signencrypt
Autocrypt: addr=marcus@dansarie.se; prefer-encrypt=mutual; keydata= mQINBFawEn4BEAC8YukDy8f3eczlE8WAcuctrjsNltPCLZDzcj3vBmiayXlXuPULOopqeuw4 +oaZqj4KqvdFBA1mzvwPll7IHePuwAoJYJr48IbIXc9MRjtLoFtd0KnhiVPUS8F2cmfzSJ8E FEv92sz6UT8/tlLEu6sNqr6/caYUivspuW5wf4f6nkSE+6rao9Nx9X03r289IPNBSZv+Y/Ym jWHDPpbT8WLUJZ+A8RsW/1oza609oAzqTkclmnRzip8wZZWNg3Q55P7onBmTIOrEz13My9r5 DWCMHyxXgFL1RJ9YW0t4yRkRm+HvOn3Vesk3m8CCGA6esHV0IPZmBOxJr3l+UQYuDiTgFufr WMpu5MvlyKGHS4fNd505DyyJY2G6eQLLrOq3nZy4qoZSL42TMxzYglexg+H6P/YsIIShk5Ch h/hNphXjrElDWhbGT5JiRWIivgSj/gq5QVBbDLR3b25n9PA0byGemfcEHLkii6EKyH7GW6v9 sgmvCmPfEfppYcOP2g9Jdt8RPitx0UBjoCzWAn0Py0NvlFDyz0FQhWDPig3yo1CG5ljb686v VBwcHJthczUV0rIyVzfmnikIb9ZjydHSX3fFwLz1IcIIX+INS58qA0SDqOoyP2WTYGZCDPVw GMMh+wMtAL2MICTr6vybFWB58m4PsI1j8Ri+AQiEkxyJauI2WQARAQABtCRNYXJjdXMgRGFu c2FyaWUgPG1hcmN1c0BkYW5zYXJpZS5zZT6JAkUEEwEIAC8CGwMCHgECF4ACGQEJCwkNCAwH CwoEBhUKCQgLAgUWAwIBAAUCWkqmHAUJBXvHHgAKCRAvY+f+raTwY6zwD/sEuXIeNbM8hhBr E5LMZFFhpVKzbToKlPifWO9SbChgDkSYx4SqrLqwD1oA6DkDK5NHO/Jj++QCN68jaOCIsT8v n++1mxHRWxEzC65I/WTLAxeLBswm9qfdpObC9ZXNSdyN+AXqzzTJR/GpUawDVe6Cc0RlYaFT 4crQHFNKYJ6lh7/xiDzWghsSKL2DuZzGdcxkMhMYFcHo26OK91OlykdfpwRT4Oe59QhBuzp+ +d76B5lCYD0QBcDRlj1pexgOcSYHPvwsdBsDL7CxHpmeEQe9RmGsGEwV+PEgXGzJr8YpSXVz 5dCR8bRAjmJZFnfiB98L1aO7lz/1Mp+OgS4vkNLLzbB4absm+Mw/s5mwDsVu3982ywJX5qoj yYySvN7YOEloUQ90aNwqMZ7s2J0rEdUvHtHLXUv5ZHwhYWt9XENiVyPyrAT58VDtHorQzBqg mj0jgaQPOBrGw6Ow1RyL046e1mYiwZYHbHoECejDCuUVQZsb8NJnKxf39YIeM02vSD3+oSfG wcEomD569XdUYqq/Y2dR7s34eteyFEQtUTZ/qRMU5x/Fw3M5zMwWEPVK7uRXySxp+jxXg3YY wNjcWC0h+YEpdhZOoWyfdaP4ZXWQSZu3wj0USsX0Ld2t7lHBkr7xm2TDU9wtH7dQwBcmIGUO T+3GvA/bGbIj1hAZNUV3q7kCDQRWsBKsARAApSTo9czkEzERsyyv9PLRHcEeBMAQ4ljXItCb Y0+fcbSXZRro7n//cJLfYUSIgC6rfFNLx8As5sVUzxLnnsL+NFjq2ic8w7+jgVyWTHhfiDdf whq2XJ/KyxvSdQsslX/oAsVFF5qUA5RPdYmDAeIn43U004s0Z1WDkIeeE1dMsoi9m5/mXS/D WDaVG6aBtr6aZbbdDV7/Ym/Vj7oPUPEsd9wpJAo9xRySx3h6qOgJBU6QXUp+vxM7PmR6boTQ h7a2coiTotmGfBM6bsQ8FYxy4fIl7tGppV0hj+cAOzKTRLaJoRsN21K92gXHp30uLv0RN1f8 vr12nt9y7VZmh+7JYtEpqz/IlMZJLNqo7Uultmv6hcZRyvxVwQoTSBtLkUTrw5SLnYOlB80J SuJgXa2hs+HrXw6bDQF9MebLMQU2hayZWc/d+Rjy0bIOKOX/hWHEKyGRorHwpoh/K3RdW5M+ OdPzsn80u5UwqMXoszp5WplcFAk361mof5fAV4D/4mOipWxqX6+2lWLwOXu3z3u7kasz7Mau 6S+9q96f05Dbj7Se3G0oTffae7/79/Ek0ieI288tlizARcOXSSO917UhlNoP74mYFX5eE66O F3mDBfxZkQ4mHHfhqbg6AfoPjSWKRkRp6+PhoFpfVGApzdUxPS0qb3ob7yjLxqotFNRDTlMA EQEAAYkERAQYAQgADwIbAgUCWH7TMwUJA5rcBwIpwV0gBBkBCAAGBQJWsBKsAAoJEMEIAA7D 4SHmu1gP/A15k6i/7SvCGzN8P4hj18jioVSO6IpZHTp8nrQdXtxK2QNbpa2sX42RQDAfkbTK sD6LPIj3C1Hivk5bmu49ZNFsfE6awt9GeqHh0pTq4K+2gv4s3MAzI85GJmTOiY5ooA922JWA QJW6kuwCkOXi0jaGkxgqZ5NW56yxdrzegY6Ly5AYr8znsqjPbQo98uW0kGwJw7Ch8JR1uZo8 6U38Oyk5oh4tbM3upvenMC5SW0EK9UjdVGCq9+HolKIbJpJR+OCF9u3PS4CVnjBJ8dfb4jD7 X/2aUSVmOQLLpCDEJvW8yoZLDm7n3poZWbubbNUYufj/GGkU1vEdTBat78AAy0lHkBIrdyrZ q7VTas6Nrd+tF/My4GpOtAZv45wJp6xo6yx3u35GYMp+/S7jTPqWz0zNq/4EJfN86dvcc0CA kTkL/EClOx3GGfkFmjEfLw3Y9zR6ZZ7okjlQM+Uqm7AfokMqstqgeETsbLZTqKKdByAjkgQR rzCbChZ+SNTmmFNtlUcn7JM55lZxsm3IUhfXx9vPKtlaC6jURYe5u/fcqpuInqSWl+DlyHAp dZkiUuZuK+kO/QpHJuTkYH5fzc6l4Af10pPeS9y7qaJ2mmMXNqRIiJqhIkNL2NypBgSJEbvW WcPtB0KiqNt8dmHwdcZhJt6cPOKxYhGi4ayKY7J5JpfpCRAvY+f+raTwY+2QD/sEqt/Mi8Uq LlPJV7NBnXa8APBMyTISLha5pKH68qtvRQy7acTTxHmau3ZA1qUdRyfxwEEZIvubljSSAzPW yYycwLmLaeTBuquEY7UAsPkc3rV9y4ZNXoAZzSz30FpzM6AcZmSzUvNzes+X6hHJf8VmN4Oj GWGmGbRAmo74AyXzIFQxTqREkJ1kPwHR8Rt3lPgtY4Dhj77G0Mk/rzTZvVPPszS2yZ2If3Qq ZIM8FsbgDt6i01ekWR7rVgycKiFhQBUo4b20BbeZmeaZ+xUPqvZMsOOnUz7XZT819sLT6UV9 nZzZ+KmCAzfqu86xtf/q2GHmfcW2F6S3Q1ShaVtWKIVHuj7Y5RfxX2vg7ZkeRKVDzYfcYWv1 dZgpQmilVmIEp0RkNvRWsTaoBOuFos3gTMr+N2ET6UrmqqIlbHZBZQEpv9+L2+ZxqNNj4MTt 4amI2iLGihwfTwMHKKZxIqISzMER80nKFVgzQpZDXnQQMzCIkJF1Cilyxlw5wYqFoyRUmZ+W kmKxD6mmVRN4rmxdQevmRfMsNb3gFhK3bYQQU4sCtUbQvDNQkb+vikYFKsMXNp0x+RHTdqz7 a2b2J2QKOsWSYYSo9XXdWBn6FiF9nz45C55FDtXQZAW9ba3JlNTw8F8AG4ig77wCdSMqfoYV My+3MEoEMbfOzqc8l4iD3063AYkERAQYAQgADwIbAgUCWkqmOAUJBXvHDAIpwV0gBBkBCAAG BQJWsBKsAAoJEMEIAA7D4SHmu1gP/A15k6i/7SvCGzN8P4hj18jioVSO6IpZHTp8nrQdXtxK 2QNbpa2sX42RQDAfkbTKsD6LPIj3C1Hivk5bmu49ZNFsfE6awt9GeqHh0pTq4K+2gv4s3MAz I85GJmTOiY5ooA922JWAQJW6kuwCkOXi0jaGkxgqZ5NW56yxdrzegY6Ly5AYr8znsqjPbQo9 8uW0kGwJw7Ch8JR1uZo86U38Oyk5oh4tbM3upvenMC5SW0EK9UjdVGCq9+HolKIbJpJR+OCF 9u3PS4CVnjBJ8dfb4jD7X/2aUSVmOQLLpCDEJvW8yoZLDm7n3poZWbubbNUYufj/GGkU1vEd TBat78AAy0lHkBIrdyrZq7VTas6Nrd+tF/My4GpOtAZv45wJp6xo6yx3u35GYMp+/S7jTPqW z0zNq/4EJfN86dvcc0CAkTkL/EClOx3GGfkFmjEfLw3Y9zR6ZZ7okjlQM+Uqm7AfokMqstqg eETsbLZTqKKdByAjkgQRrzCbChZ+SNTmmFNtlUcn7JM55lZxsm3IUhfXx9vPKtlaC6jURYe5 u/fcqpuInqSWl+DlyHApdZkiUuZuK+kO/QpHJuTkYH5fzc6l4Af10pPeS9y7qaJ2mmMXNqRI iJqhIkNL2NypBgSJEbvWWcPtB0KiqNt8dmHwdcZhJt6cPOKxYhGi4ayKY7J5JpfpCRAvY+f+ raTwY8QcD/9XUx8phbJaqpZpIEsay2OsXk0I0MFlmKqgHhi1YgLZoNk6UzqT+/GDrHsBN7lY j5wHtBHLONS7/CbYgyHh1JnuIxRBp2VM4bd7TXpmFpf6fDI4n5JFE5t0ThzXoB8fLY+7Onyl sszvfz83VGEYrmJNKCLKezjvj6JiuUfeImAjT8syGgxXzX+eSjJWegW+nQ/EWqBF6TfqhxgO bb14pbEelbAxdAe6rY+eXsB2B3UNlQz/OPiOykvdi5PCQjhGDI54ogLT7kH5jznouf1zCkC9 NQpHTQVGI/gYR9+VbRAcLKvyiI6it0JA92GZDqmGhmq4GJrHCJfhFW9wh4F0faaHoyqFbOu/ 5gfmfysMoedLx5GAeU03NTedmPs2g4DsAdyh+FdUn/Q5lX/VrsR5IbIO0p0I8E7+A1yE6xNq zDjbBOkxLj3uyOcmx70kQSO9l0H5T+dHUFvJqLzG3BQ6otBB7w8lNlBDTRguUeHNcMhvot1G zJBt++8Jpp1TY3IEuNlMiBpL+iPqgViqyReDsjmVaJbtP/7XM+lZLTM+LVvkFQgt+t3r2NgA ZEj91zKYOsPB1V/0USeGkpoir6BXVPvg2WOunEd3QxkxElNsGH9uxfadNgSS4bn9tib2TGy/ urm1fULsuIOiJR6vMQ1fjjJoPnM8b6dkHSQ7y3+PiPhTpbkCDQRWsBLLARAAyxyKDIPLq3FD 9xQTw/5L3Mw81uxNKpreLKPRJESzDGYmytSi77I639jhTEZf4ktz/OMjX5+tYTfcI2a5xgy2 tlKvGBAOn5anwCTtQ1CUG1EiN1w+qYAQXOAb04/sh/swlkx5ZV3jvJshhQqiG5N0WDAlIXzR /4MYsuMhyHJVlu/JlZJAogDF9q+ZmvUI0RVhfKsvvnastUH4qdCAloWocU+npw79jbRWIX1C wtG2Wt5/VWvG10+4guEQoyaZz5lGwOEnRXwyLmrylZxhavP4mJVHIDVQsCGDoLbKmPVwU2dD I3bZem1dvPrztuplDFqvnHIABXgPqL/yrWQ2BKxsOr5eRa4aNL2Sa8sYz2QYBE2EwU2C4lKB J+pkTE8AmEJniFVuhMoWhFHXTjzauU7KPRVrQZuakap+2M2h0DiaOkGLnak3KZQX6zp5OTXc v0M44nx3T7ZB3p7i5N41cmE1bqDaXtvl239tscyVruGCpEpS1OpBFHYkKk/e8Xiwdaddh0Rw lIAJqsFzFt93BkGcX03C/saI1MQSDs77yrCWPXotMHyg1aM7AAeKqDTFCUvwlPPauRfSBQhb UfL0DpvpSKRWJFuakdeDSzvfrhe3GOKaQoPwNWcLk0kOLBnO2obaJbuTEmd8D54AKUoSH6eJ mjk2mNY1R+GNRczkM1Ue1yEAEQEAAYkCJQQYAQgADwIbDAUCWH7TMwUJA5rb6AAKCRAvY+f+ raTwY9jcD/49jEB5A1YjXzIfNXhJjFH/7jpL6lk8xfK8dDD6e1OsOEqu6l7Ito+7HrDgn7RV urrWXTehCQ95R/uUeXAErHIVAPWt32lm9umB+lDB8KXL6sh3WbavQdzk4UE/hpOKPDX+assu u7GI3ZXY0UzhsRIz1gw6LoZVUqvYIP8S2y+bfDSWkqjwU5ExAi5cuGH8k/LUIbpdb1ALggia kPi+hXRtfGikiw3UY7LtCv5MjkeWL43Prj0w0kdWyWup+/KunI3DsjcvSVvr1nWpuVwQm8WA FfOf85+qL8ACB+2aknGuHot948UcJvSaTbYMFk0HPUVDfDPpUlBmVMZft1Akxa2EGK877uM6 +gC9roB7BF8b/CyEx3QnpvDK53iCns1qaLjL3P8sRJF+K7bHJm0k58BpDH5Yg1Ia8h4ihPEs U0FQznREdR28xsFHzC7NfdDhYTCRNFee4AVB3MDmfdBOiPprAhusSa/h2Q1w3GjBQtI30Pr2 ZaVl9TVvFE/uIQtheW8MQgRgSOqwV6JVg8Cu/Tt+88C2ngLGAp2ty6rZ6xUcKr1gup/OkX8o MIwDmFFKrnz9GBEBh6FHBz27wHANojHN6KJAPRpIY1SClBxIn/vkGdhlL9cgQgieMP3LixbQ BdBhTJWHjiWh+HZzuFuLkh+wpraJEbvsmPPMSPfnjsMrmokCJQQYAQgADwIbDAUCWkqmOAUJ BXvG7QAKCRAvY+f+raTwY1BFD/0e1Vr993CDFGjTJFO24O14xp6JY5L9b80LNqOvBeLnIgF+ HssKxP8Vh0CWCMO7EAA1dAIq8iBzWLlqTQ4xnMuiIXA/y5HP7noVIWNxUBu8tnHZU/1mlN5Z tCE2rLJ8VjN2Wz4zyi0xnKjALkLflmK751YDZvctgRmx3ous1k8LpZwKrzL8NYeLmG5uAENk tz/FI2RLIjijfogdaSvZKBOMe6Gqtb9WdzoMP9kKj6uEqwWUoZB19Jy6rTxB0jjoAwkXvHjT WaoqDlSPyldsDsCXF4FeYOpq53N59yugLl3xN0UUQscAczYdUgONeTL5SY+2ILtwTRgWPO2S SOC88PPHQMK2XhZqCHiVXMU7BYbXGVXqV62/1gpWTw+5IAiIo4LqlWY7oQiuc+BL/z0p0Vap Boexa7rTa3T1ytqhpeQzqDLtkEVlYv+LQ6qB3cRtCNmNAi3nwmzKnElumimz0f9fsbhNMMAC 6DQnksB74rakgyNLZSaCCqt9lb2tPHYF+NPGqFxSW8r62yrRUNx2phvFO2j/B1f0NMm7h7PN qbkNv0b9nQPf2MSYMTavN2EZ4/vfhAfOf07Z55ahpA+zfAfeQvrEPY2JutdET4jpa9xtSuoe S3LbYs7Sy2OUpbmIWM/pCo9OUZsMxbWgn1x1A/LEWElPx4HioOlW6SnYvKOiOw==
Message-ID: <db984964-799a-4c06-ceaa-ca96e9ba5d3b@dansarie.se>
Date: Thu, 15 Nov 2018 23:00:32 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.2.1
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/nNdtijNVnfXxP7xL12Hzd2GYqH8>
Subject: [Ntp] WGLC comments on draft-ietf-ntp-using-nts-for-ntp-14
X-BeenThere: ntp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <ntp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ntp>, <mailto:ntp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp/>
List-Post: <mailto:ntp@ietf.org>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ntp>, <mailto:ntp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Nov 2018 22:00:39 -0000

All,

Ragnar and I spent a couple of hours yesterday going over NTS4NTP draft
14. Overall, we are very happy with the current state of the draft. Our
remaining concerns and a few general comments are as follows:

* In Section 1.1, we would still like resilience to be an express
objective of NTS. A possible wording could be "Attacks on or faults in
parts of the NTS infrastructure should not completely prohibit clients
from performing time synchronization. In particular, security
enhancements to the NTP protocol should not increase the protocol's
ability to withstand attacks."

* Re Section 3, we still feel that TLS 1.3 should be the lowest
acceptable TLS version. It is certainly true that requiring TLS 1.3
would probably limit short term adaption of NTS. Our opinion, however,
is that concerns for for the short term should not take priority over
the long term where this could lead to servers having to support TLS 1.2
for a long time if TLS 1.2-only client implementations were to emerge
after the draft's adaption as an RFC.

* Our suggested NTP Server Negotiation record from draft-dansarie-nts-00
has been reworked by Daniel Franke into Sections 4.1.7 and 4.1.8
following comments in previous WG meetings. After thorough discussion,
Ragnar and I now agree that the design in current draft is sound and
that there is no need for the NTS-KE protocol to support lists of
preferred/assigned servers in server/port negotiation records. Such
lists would add to protocol complexity while only satisfying a fringe
requirement that can be achieved on the implementation side without this
addition. We only have one minor comment to the wording: In Section
4.1.7, paragraph 2: "If no record of this type is sent, the client SHALL
interpret this [...]", we believe that SHALL is to strong of a
requirement and that a SHOULD would suffice.

* In Section 5.6, we support the addition of an additional padding field
and the reasoning behind it.

* In Section 7.1, the service name has been changed to "ntske". We
support this. The section reserves a TCP port only for NTS-KE. It has
been suggested to us that it is customary to register both TCP and UDP
ports with the same number, but we're unsure what the current practice
is. Considering that NTP's registered port is in the system port range,
we think that we should try to get an NTS-KE port in the same range,
unless there are strong reasons not to.

* In Section 9.3, it is suggested that clients should "not process time
packets from servers if the time computed from them falls outside the
validity period of the server's certificate." We believe that there is a
risk that this could be interpreted as meaning that clients should
reperform an NTS-KE handshake upon expiry of the certificate that was
used by the NTS-KE server to provide the client with its initial supply
of cookies. In the worst case, this could lead to an accidental DoS
attack as many clients try to perform a new NTS-KE handshake at the
expiry time of a server's old certificate. We suggest adding a sentence
like "Clients SHOULD NOT perform a new NTS-KE handshake solely based on
the fact that the certificate used by the NTS-KE server in a previous
handshake has expired, if the client has previously received valid NTS
protected NTP replies that lie within the certificate's validity time."

* Since there is a current draft that attempts to solve the problem
described in Section 9.4, adding a reference there to
draft-schiff-ntp-chronos-01 could be a good idea.

In conclusion: We have no major objections to the draft at this point.
With the exception of our comment on Section 9.3, none of our comments
are of great importance to us and we will yield if there is no
agreement. Our concerns regarding Section 9.3 need to be addressed in
one way or another.

We would like to thank everyone who have contributed to the draft and
made the effort to read and comment on it. We look forward to your
comments on our suggestions.

Kind regards,
Marcus Dansarie and Ragnar Sundblad