[secdir] draft-deshpande-secevent-http-multi-set-push-03 ietf last call Secdir review
Scott Kelly via Datatracker <noreply@ietf.org> Sun, 30 August 2026 00:00 UTC
Return-Path: <noreply@ietf.org>
X-Original-To: secdir@ietf.org
Delivered-To: secdir@mail2.ietf.org
Received: from [10.244.8.80] (gaia.k8s.ietf.org [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id 33E17131A03CA; Sat, 29 Aug 2026 17:00:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788048004; bh=syuG0rB3QYnOlqc+9ZHb9qT9M4i4TLGTMm0GNAKLS7Y=; h=From:To:Cc:Subject:Reply-To:Date; b=CY6uttWRT+0bHyOy30AVPMKd1a/zS28EbKONIeqOFBdF3z9y21UtNVEG5b1hCEv4m ywzkupCjNsk8gkRXetBwxXKkKrpHHioI7+AH7zvKSktec8ebjduVyARq0/zJyO+xzH 80uSYhHWDf60K7Xh67u60YCcxme48IhdP3tC3Sbg=
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Scott Kelly via Datatracker <noreply@ietf.org>
To: secdir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.73.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <178804800397.202945.12279075182481981538@dt-datatracker-6669c7b496-s9mrn>
Date: Sat, 29 Aug 2026 17:00:04 -0700
Message-ID-Hash: KHN3ULF47LPXHX5GQEIPQ5DY6Z3DYXVU
X-Message-ID-Hash: KHN3ULF47LPXHX5GQEIPQ5DY6Z3DYXVU
X-MailFrom: noreply@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-secdir.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-deshpande-secevent-http-multi-set-push.all@ietf.org, last-call@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: Scott Kelly <scott@hyperthought.com>
Subject: [secdir] draft-deshpande-secevent-http-multi-set-push-03 ietf last call Secdir review
List-Id: Security Area Directorate <secdir.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/3DgeYE4AO7wB0zw3MVsSeqUMJt4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Owner: <mailto:secdir-owner@ietf.org>
List-Post: <mailto:secdir@ietf.org>
List-Subscribe: <mailto:secdir-join@ietf.org>
List-Unsubscribe: <mailto:secdir-leave@ietf.org>
Document: draft-deshpande-secevent-http-multi-set-push Title: Push-Based Delivery For Multiple Security Event Tokens (SET) Using HTTP Reviewer: Scott Kelly Review result: Ready I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. The summary of the review is ready. >From the abstract, this specification defines how multiple Security Event Tokens (SETs) can be delivered to an intended recipient using HTTP POST over TLS. At the end of the introduction, the doc says “This specification will handle all the use cases and scenarios for the [RFC8935] and make it more extensible to support multiple SETs per one outbound POST request.” So, I’m assuming that this doc is extending RFC8935 to support multiple SETs. The security considerations section starts with “The Security Considerations of [RFC8935], [RFC9846], and Section 17 of [RFC9110] apply to this specification.” Section 17 of RFC9110 is the Security Considerations section of that doc, so I would suggest changing this to say “The Security Considerations of [RFC8935], [RFC9846], and [RFC9110] apply to this specification.” I think the security considerations section does a good job and covers what it should. It does cover a few things I naively thought must be covered by 8935, but after double-checking, I think this document adds some important clarifications. I don’t have any suggestions for improvements.
- [secdir] draft-deshpande-secevent-http-multi-set-… Scott Kelly via Datatracker