[secdir] draft-deshpande-secevent-http-multi-set-push-03 ietf last call Secdir review

Scott Kelly via Datatracker <noreply@ietf.org> Sun, 30 August 2026 00:00 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: secdir@ietf.org
Delivered-To: secdir@mail2.ietf.org
Received: from [10.244.8.80] (gaia.k8s.ietf.org [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id 33E17131A03CA; Sat, 29 Aug 2026 17:00:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788048004; bh=syuG0rB3QYnOlqc+9ZHb9qT9M4i4TLGTMm0GNAKLS7Y=; h=From:To:Cc:Subject:Reply-To:Date; b=CY6uttWRT+0bHyOy30AVPMKd1a/zS28EbKONIeqOFBdF3z9y21UtNVEG5b1hCEv4m ywzkupCjNsk8gkRXetBwxXKkKrpHHioI7+AH7zvKSktec8ebjduVyARq0/zJyO+xzH 80uSYhHWDf60K7Xh67u60YCcxme48IhdP3tC3Sbg=
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Scott Kelly via Datatracker <noreply@ietf.org>
To: secdir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.73.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <178804800397.202945.12279075182481981538@dt-datatracker-6669c7b496-s9mrn>
Date: Sat, 29 Aug 2026 17:00:04 -0700
Message-ID-Hash: KHN3ULF47LPXHX5GQEIPQ5DY6Z3DYXVU
X-Message-ID-Hash: KHN3ULF47LPXHX5GQEIPQ5DY6Z3DYXVU
X-MailFrom: noreply@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-secdir.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-deshpande-secevent-http-multi-set-push.all@ietf.org, last-call@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: Scott Kelly <scott@hyperthought.com>
Subject: [secdir] draft-deshpande-secevent-http-multi-set-push-03 ietf last call Secdir review
List-Id: Security Area Directorate <secdir.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/3DgeYE4AO7wB0zw3MVsSeqUMJt4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Owner: <mailto:secdir-owner@ietf.org>
List-Post: <mailto:secdir@ietf.org>
List-Subscribe: <mailto:secdir-join@ietf.org>
List-Unsubscribe: <mailto:secdir-leave@ietf.org>

Document: draft-deshpande-secevent-http-multi-set-push
Title: Push-Based Delivery For Multiple Security Event Tokens (SET) Using HTTP
Reviewer: Scott Kelly
Review result: Ready

I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG. These comments
were written primarily for the benefit of the security area directors. Document
editors and WG chairs should treat these comments just like any other last call
comments. The summary of the review is ready.

>From the abstract, this specification defines how multiple Security Event
Tokens (SETs) can be delivered to an intended recipient using HTTP POST over
TLS. At the end of the introduction, the doc says “This specification will
handle all the use cases and scenarios for the [RFC8935] and make it more
extensible to support multiple SETs per one outbound POST request.” So, I’m
assuming that this doc is extending RFC8935 to support multiple SETs.

The security considerations section starts with “The Security Considerations of
[RFC8935], [RFC9846], and Section 17 of [RFC9110] apply to this specification.”

Section 17 of RFC9110 is the Security Considerations section of that doc, so I
would suggest changing this to say “The Security Considerations of [RFC8935],
[RFC9846], and [RFC9110] apply to this specification.”

I think the security considerations section does a good job and covers what it
should. It does cover a few things I naively thought must be covered by 8935,
but after double-checking, I think this document adds some important
clarifications. I don’t have any suggestions for improvements.