Re: [OAUTH-WG] AD Review of draft-ietf-oauth-spop-10

Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com> Sun, 17 May 2015 02:31 UTC

Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 383651A1B5A for <oauth@ietfa.amsl.com>; Sat, 16 May 2015 19:31:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GZJwwIz_5oXb for <oauth@ietfa.amsl.com>; Sat, 16 May 2015 19:31:36 -0700 (PDT)
Received: from mail-qk0-x230.google.com (mail-qk0-x230.google.com [IPv6:2607:f8b0:400d:c09::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 619E71A1B56 for <oauth@ietf.org>; Sat, 16 May 2015 19:31:36 -0700 (PDT)
Received: by qkgx75 with SMTP id x75so92140449qkg.1 for <oauth@ietf.org>; Sat, 16 May 2015 19:31:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:content-type:mime-version:subject:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=K8wCH7Nn9asNphH10Nju0vQ/wIt1xvJQRwKgllrL9UQ=; b=S+JslPOi7iZEl0Yc9Xe8fF/5D/LfOzgh9fWUVCaSNFLz5Yk76kkfDDcxH48eABtXaY xSnfcz1EeMrsZlBABRmuwXsZEAUpA9x4z9e1pzEXunU4xcnmI8OiacN2dDP8+rk1PJIM 4orFyWm2IY/KyprprxWDCFOkW01VHOvtZosDIBLowKMHbBYYNP1plKT5HWjDHk2JXVTz dl2wNCfLPcsfZJDqxxlfQHyip6Wqy4raJcEJkCv+o3zAZSIiao5/f2Q5WMjO4LZ2z41O Tx0/9hNKXRJdFtLg0/EzhDTeC4JqTuZkxR76/MeL453E6d9/jR35dWtEyg3wTh6liZxt JZiw==
X-Received: by 10.140.19.169 with SMTP id 38mr21023360qgh.75.1431829895644; Sat, 16 May 2015 19:31:35 -0700 (PDT)
Received: from [192.168.1.3] (209-6-114-252.c3-0.arl-ubr1.sbo-arl.ma.cable.rcn.com. [209.6.114.252]) by mx.google.com with ESMTPSA id 75sm4188968qhw.41.2015.05.16.19.31.33 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sat, 16 May 2015 19:31:34 -0700 (PDT)
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
X-Google-Original-From: Kathleen Moriarty <Kathleen.Moriarty.ietf@gmail.com>
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (1.0)
X-Mailer: iPhone Mail (11D257)
In-Reply-To: <89A5F51C-DE0E-4B8D-9D3B-6D1142A31859@ve7jtb.com>
Date: Sat, 16 May 2015 22:31:35 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <E8C283B3-C674-4859-975C-EDCA3D1C006F@gmail.com>
References: <CAHbuEH4rOsD-TXbL9_+6HrK3_tpoPrfKVLqcJ4f0k1nFCFunMQ@mail.gmail.com> <89A5F51C-DE0E-4B8D-9D3B-6D1142A31859@ve7jtb.com>
To: John Bradley <ve7jtb@ve7jtb.com>
Archived-At: <http://mailarchive.ietf.org/arch/msg/oauth/zQqIGFf8ad7nstB_no4Vvs1o9Co>
Cc: "oauth@ietf.org" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] AD Review of draft-ietf-oauth-spop-10
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 17 May 2015 02:31:38 -0000

Hi John,

Thank you.  I'll review it tomorrow and start the processing so last call can start on Monday.

Best regards,
Kathleen 

Sent from my iPhone

> On May 16, 2015, at 7:12 PM, John Bradley <ve7jtb@ve7jtb.com> wrote:
> 
> Hi Kathleen,
> 
> I have made the two edits and updated the draft.
> 
> John B.
> 
>> On Apr 18, 2015, at 12:39 PM, Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com> wrote:
>> 
>> Hello,
>> 
>> I just reviewed draft-ietf-oauth-spop-10 and am thinking more should be said about TLS 1.2 in the security recommendations.  I see that it is recommended through RFC6819 that just says: 
>> 
>> Attacks can be mitigated by using transport-layer mechanisms such as
>>   TLS [RFC5246].  A virtual private network (VPN), e.g., based on IPsec
>>   VPNs [RFC4301], may be considered as well.
>> 
>> 
>> And more has been said in recent publications.  Since this particular draft is addressing a threat exposed when TLS is not in use, the language from the last draft would be better, requiring at least TLS 1.2 and referring to the TLS BCP.
>> 
>> The only other point from my review is a nit:
>> At the end of section 4.4, there should be quotes around both instances of "plain".
>> 
>> Once this has been addressed, we can start IETF last call.
>> 
>> Thank you!
>> -- 
>> 
>> Best regards,
>> Kathleen
>> _______________________________________________
>> OAuth mailing list
>> OAuth@ietf.org
>> https://www.ietf.org/mailman/listinfo/oauth
>