[secdir] secdir review of draft-ietf-marf-as-14

Scott Kelly <scott@hyperthought.com> Sun, 22 April 2012 18:23 UTC

Return-Path: <scott@hyperthought.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7DF1021F865C for <secdir@ietfa.amsl.com>; Sun, 22 Apr 2012 11:23:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.265
X-Spam-Level:
X-Spam-Status: No, score=-3.265 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id f0G9s9WKBeEK for <secdir@ietfa.amsl.com>; Sun, 22 Apr 2012 11:23:02 -0700 (PDT)
Received: from smtp130.dfw.emailsrvr.com (smtp130.dfw.emailsrvr.com [67.192.241.130]) by ietfa.amsl.com (Postfix) with ESMTP id A617821F8648 for <secdir@ietf.org>; Sun, 22 Apr 2012 11:23:02 -0700 (PDT)
Received: from localhost (localhost.localdomain [127.0.0.1]) by smtp29.relay.dfw1a.emailsrvr.com (SMTP Server) with ESMTP id 3D6D93982F2; Sun, 22 Apr 2012 14:23:02 -0400 (EDT)
X-Virus-Scanned: OK
Received: by smtp29.relay.dfw1a.emailsrvr.com (Authenticated sender: scott-AT-hyperthought.com) with ESMTPSA id B25993982F5; Sun, 22 Apr 2012 14:23:01 -0400 (EDT)
From: Scott Kelly <scott@hyperthought.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Date: Sun, 22 Apr 2012 11:23:00 -0700
Message-Id: <AA35B8D1-7788-4CDC-852B-0D48EAD1C201@hyperthought.com>
To: draft-ietf-marf-as.all@tools.ietf.org, secdir@ietf.org, iesg@ietf.org
Mime-Version: 1.0 (Apple Message framework v1084)
X-Mailer: Apple Mail (2.1084)
Subject: [secdir] secdir review of draft-ietf-marf-as-14
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 22 Apr 2012 18:23:03 -0000

I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG.  These comments were written primarily for the benefit of the security area directors.  Document editors and WG chairs should treat these comments just like any other last call comments.

The Abuse Reporting Format (ARF) is used to report email abuse feedback between email operators, or from email operators to end user network access operators. This document is an applicability statement for using the ARF in these two contexts.

The security considerations section refers the reader to the security considerations discussions in RFCs 5965 and 6449, but also contains a detailed discussion of various concerns. I see no security issues with this document.