[rtcweb] Kathleen Moriarty's No Objection on draft-ietf-rtcweb-rtp-usage-24: (with COMMENT)

"Kathleen Moriarty" <Kathleen.Moriarty.ietf@gmail.com> Tue, 09 June 2015 20:36 UTC

Return-Path: <Kathleen.Moriarty.ietf@gmail.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CCD151B30D9; Tue, 9 Jun 2015 13:36:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_ADSP_CUSTOM_MED=0.001, FREEMAIL_FROM=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id I3bCdQRsPP-m; Tue, 9 Jun 2015 13:36:11 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 85D9F1B30C4; Tue, 9 Jun 2015 13:36:11 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Kathleen Moriarty <Kathleen.Moriarty.ietf@gmail.com>
To: The IESG <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.0.3.p2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150609203611.18304.3157.idtracker@ietfa.amsl.com>
Date: Tue, 09 Jun 2015 13:36:11 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/rtcweb/CMmOyOaEk2Izxc7is6eNwJj6FE0>
X-Mailman-Approved-At: Tue, 09 Jun 2015 14:34:04 -0700
Cc: rtcweb@ietf.org
Subject: [rtcweb] Kathleen Moriarty's No Objection on draft-ietf-rtcweb-rtp-usage-24: (with COMMENT)
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb/>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Jun 2015 20:36:12 -0000

Kathleen Moriarty has entered the following ballot position for
draft-ietf-rtcweb-rtp-usage-24: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-rtcweb-rtp-usage/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thank you for your work on this well-written draft.  The SecDir review
picked up on a number of nits that should be corrected, tow in the
Security considerations section in particular.
The full review can be found here:
http://www.ietf.org/mail-archive/web/secdir/current/msg05759.html

And the specific fixes for the security considerations text is as
follows:
The security considerations section was comprehensive and security
impacts were taken into account throughout this draft.  I have two small
NIT’s about the security section that I would like improved, and I feel
these are rather small:  First, in the paragraph in the security section
that starts “RTCP packets convey a Canonical Name…”  the authors state
that the CNAME generation algorithm in described in section 4.9 – it
isn’t, section 4.9 references RFC7022 for the generation algorithm. 
Second, the last paragraph on page 39, starting with “Providing source
authentication in multi-party…” ends the page with a large security
warning.   Please include a reference in that paragraph in the security
considerations and possibly to the appropriate draft/RFC which discusses
that issue in some more depth.