[secdir] SECDIR review of draft-ietf-payload-rtp-klv-02.txt

Alexey Melnikov <alexey.melnikov@isode.com> Sat, 28 January 2012 19:22 UTC

Return-Path: <alexey.melnikov@isode.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 31A1121F842F; Sat, 28 Jan 2012 11:22:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.416
X-Spam-Level:
X-Spam-Status: No, score=-102.416 tagged_above=-999 required=5 tests=[AWL=0.183, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gpOGtM4xFILQ; Sat, 28 Jan 2012 11:22:11 -0800 (PST)
Received: from rufus.isode.com (cl-125.lon-03.gb.sixxs.net [IPv6:2a00:14f0:e000:7c::2]) by ietfa.amsl.com (Postfix) with ESMTP id 874ED21F8543; Sat, 28 Jan 2012 11:22:03 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1327778522; d=isode.com; s=selector; i=@isode.com; bh=ku4jjYDg3PiTuywExSHKLz0yt7KrUwCB1OSx9SD1x5U=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=gW1wlBdRCaV28J8f19Fa1hLIjwUmxe3ns/J7vkR0lbcRFOvWKVhRTRSV6mEEF+FbTHn0pa g5VCmQxwPEl+iK2k4fPPNaKW5j43jfqAYmgKZN0sY/pyA1sWW51vPdgUFy/Hh3z4OrvNnQ 1in5K29oHQDAxP3Ey9rpM3ybiUgPfSs=;
Received: from [188.28.107.210] (188.28.107.210.threembb.co.uk [188.28.107.210]) by rufus.isode.com (submission channel) via TCP with ESMTPSA id <TyRK1AAV54t8@rufus.isode.com>; Sat, 28 Jan 2012 19:22:00 +0000
Message-ID: <4F244AE1.5000301@isode.com>
Date: Sat, 28 Jan 2012 19:22:09 +0000
From: Alexey Melnikov <alexey.melnikov@isode.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:8.0) Gecko/20111105 Thunderbird/8.0
To: "iesg@ietf.org" <iesg@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>, draft-ietf-payload-rtp-klv.all@tools.ietf.org
MIME-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Subject: [secdir] SECDIR review of draft-ietf-payload-rtp-klv-02.txt
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 28 Jan 2012 19:22:12 -0000

I have reviewed this document as part of the security directorate's 
ongoing effort to review all IETF documents being processed by the IESG. 
  These comments were written primarily for the benefit of the security 
area directors.  Document editors and WG chairs should treat these 
comments just like any other last call comments.

This document specifies the payload format (and the corresponding media 
type) for packetization of KLV (Key-Length-Value) Encoded Data, as 
defined by the Society of Motion Picture and Television Engineers 
(SMPTE) in SMPTE 336M, into the Real-time Transport Protocol (RTP).

The document is well written. Its Security Considerations section talks 
about several ways of providing RTP payload confidentiality, integrity 
and source authenticity. It also talks about causing denial of service 
in naive decoders by specially crafted packets. I can't think of other 
things that needs to be covered in this section.