Re: [precis] Secdir last call review of draft-ietf-precis-7564bis-07

Peter Saint-Andre <stpeter@stpeter.im> Tue, 13 June 2017 23:02 UTC

Return-Path: <stpeter@stpeter.im>
X-Original-To: precis@ietfa.amsl.com
Delivered-To: precis@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9084C1293FF; Tue, 13 Jun 2017 16:02:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.72
X-Spam-Level:
X-Spam-Status: No, score=-2.72 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=stpeter.im header.b=i6v+q1k6; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=LRiZ4i3H
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id D0y0x0B6-TiA; Tue, 13 Jun 2017 16:02:30 -0700 (PDT)
Received: from out4-smtp.messagingengine.com (out4-smtp.messagingengine.com [66.111.4.28]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 655E1126D85; Tue, 13 Jun 2017 16:02:30 -0700 (PDT)
Received: from compute2.internal (compute2.nyi.internal [10.202.2.42]) by mailout.nyi.internal (Postfix) with ESMTP id D4DE020779; Tue, 13 Jun 2017 19:02:29 -0400 (EDT)
Received: from frontend1 ([10.202.2.160]) by compute2.internal (MEProxy); Tue, 13 Jun 2017 19:02:29 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=stpeter.im; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-sender :x-me-sender:x-sasl-enc:x-sasl-enc; s=fm1; bh=hYpJEJxhfVVoKbe4O9 FJfQCUGyOkOZtXIGVtx8SZlK4=; b=i6v+q1k6/3RkDdyRWdbVjaKk52EJbu9vBG S1ZCp9vy8bvDPu4MjFGYEU26QLhcBr+D88COd7cbIhLEGy8eOCbgvvDpsg1Zrv12 BvwwpPEJ0dTzMzCCBEbKBAvEFPgxg6XjEhcIGE6TKiS6miSiOLaVUxJ2R92vjybS 8N64tHDp9QZYYys6FzQ95yq7KL7g8m4BhAnaFoeTRXLaibxPAHiVHfhDdfBXdilY X3/igy/HJ/5hnF772sPxcfRkwB2fw0+smNnNI/JD4RaBbl52o2zVqIPH70/O+eCS Ul4X0BkVWkijuLoRnCmtr52dQz9NCYEwaK0FQaAWo1ZougjnJcwQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-sender:x-me-sender:x-sasl-enc:x-sasl-enc; s= fm1; bh=hYpJEJxhfVVoKbe4O9FJfQCUGyOkOZtXIGVtx8SZlK4=; b=LRiZ4i3H Y+t0L4SqQhDd5ky1syaUs/W1PWVGW74C+Ox/+xXemYFQxSyK2TXxsLDfy8YdvgBb 61HtmKw1RVV1cC25vkvpwGpg98D10LTA26xdS1VsVbLuhmCBIIZoz6PhTFo8CWnB QAN2i+Tv9K8EocfEQOplPwvtaoLKZwEXiupJvLeVt9lnq/prppaVan4O0vSoLw01 zaCvzCrTSjDSzjLF2ZA3n6Y4orSehQAkCaCWSBYhnOcQW0nRhUnOSu97w7LDFrtZ 4fmPaWjpE95PN0Vw+KoIajctdpRx12dyc55F8HDWedHobAFu3lDz6KenNyBRA427 rWLa3Ibjw641pA==
X-ME-Sender: <xms:BW9AWWidEV8z2QL9-UpbyCVO2T6QChCgygcM_lP7xDjNf86YEVV-1Q>
X-Sasl-enc: e0uQ2UhIxT09nbCV9NHeq4i1ouZ7RDKecz5XaNtGaO5W 1497394949
Received: from aither.local (unknown [76.25.4.24]) by mail.messagingengine.com (Postfix) with ESMTPA id 2ACD47E7A3; Tue, 13 Jun 2017 19:02:29 -0400 (EDT)
To: Matthew Miller <linuxwolf+ietf@outer-planes.net>, secdir@ietf.org
References: <149736681626.7439.2555177998557552719@ietfa.amsl.com>
Cc: draft-ietf-precis-7564bis.all@ietf.org, ietf@ietf.org, precis@ietf.org
From: Peter Saint-Andre <stpeter@stpeter.im>
Message-ID: <8ea90b99-3005-0afb-da93-63cd1abfc905@stpeter.im>
Date: Tue, 13 Jun 2017 17:02:28 -0600
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:45.0) Gecko/20100101 Thunderbird/45.8.0
MIME-Version: 1.0
In-Reply-To: <149736681626.7439.2555177998557552719@ietfa.amsl.com>
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/precis/N5gJBS1u-8lFVMoPGN2WeTitl8A>
Subject: Re: [precis] Secdir last call review of draft-ietf-precis-7564bis-07
X-BeenThere: precis@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Preparation and Comparison of Internationalized Strings <precis.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/precis>, <mailto:precis-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/precis/>
List-Post: <mailto:precis@ietf.org>
List-Help: <mailto:precis-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/precis>, <mailto:precis-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jun 2017 23:02:33 -0000

Hi Matt, thanks for the review - it's much appreciated.

Just so you know: through discussion of Daniel Migualt's secdir review
of 7700bis (we're progressing them all together this time!), I realized
that it might be help to add another example of visually confusing
characters to 7564bis, so I plan to mention CYRILLIC SMALL LETTER A
U+0430 vs. LATIN SMALL LETTER A U+0061 (which will be more familiar to
readers than the Cherokee characters already in the document).

Peter

On 6/13/17 9:13 AM, Matthew Miller wrote:
> Reviewer: Matthew Miller
> Review result: Ready
> 
> I have reviewed this document as part of the security directorate's
> ongoing effort to review all IETF documents being processed by the
> IESG.  These comments were written primarily for the benefit of the
> security area directors.  Document editors and WG chairs should
> treat these comments just like any other last call comments.
> 
> Document: draft-ietf-precis-7564bis-07
> Reviewer: Matthew A. Miller
> Review Date: 2017-06-13
> IETF LC End Date: 2017-06-13
> IESG Telechat date: 2017-07-06
> 
> Summary:
> 
> This document is ready to be published as a Standards Track document.
> 
> This document defines a framework application protocols use to
> prepare, compare, and enforce conformance of internationalized strings.
> It obsoletes RFC 7564.
> 
> This document is well written, and reinforces the security concerns
> discussed in Section 12 with references in the most relevant sections
> throughout the document.  While much of it essentially proclaims
> "be aware herein be dragons", the arguments for not proscribing more
> are well laid out.
> 
> Major Issues:  NONE
> 
> Minor Issues: NONE
> 
> Nits: NONE
> 
> 
> _______________________________________________
> precis mailing list
> precis@ietf.org
> https://www.ietf.org/mailman/listinfo/precis
>