[secdir] secdir review of draft-ietf-behave-dns64-09

scott@hyperthought.com Wed, 09 June 2010 18:28 UTC

Return-Path: <scott@hyperthought.com>
X-Original-To: secdir@core3.amsl.com
Delivered-To: secdir@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 1769C3A680D for <secdir@core3.amsl.com>; Wed, 9 Jun 2010 11:28:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.999
X-Spam-Level:
X-Spam-Status: No, score=-0.999 tagged_above=-999 required=5 tests=[BAYES_50=0.001, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Lnk9z388OlUO for <secdir@core3.amsl.com>; Wed, 9 Jun 2010 11:28:57 -0700 (PDT)
Received: from smtp242.iad.emailsrvr.com (smtp242.iad.emailsrvr.com [207.97.245.242]) by core3.amsl.com (Postfix) with ESMTP id 1284E3A6783 for <secdir@ietf.org>; Wed, 9 Jun 2010 11:28:57 -0700 (PDT)
Received: from relay14.relay.iad.mlsrvr.com (localhost [127.0.0.1]) by relay14.relay.iad.mlsrvr.com (SMTP Server) with ESMTP id 6A1E323A832; Wed, 9 Jun 2010 14:28:58 -0400 (EDT)
Received: from dynamic4.wm-web.iad.mlsrvr.com (dynamic4.wm-web.iad.mlsrvr.com [192.168.2.153]) by relay14.relay.iad.mlsrvr.com (SMTP Server) with ESMTP id 5F7E923A811; Wed, 9 Jun 2010 14:28:58 -0400 (EDT)
Received: from hyperthought.com (localhost [127.0.0.1]) by dynamic4.wm-web.iad.mlsrvr.com (Postfix) with ESMTP id 3AF3A1D48073; Wed, 9 Jun 2010 14:28:58 -0400 (EDT)
Received: by apps.rackspace.com (Authenticated sender: scott@hyperthought.com, from: scott@hyperthought.com) with HTTP; Wed, 9 Jun 2010 11:28:58 -0700 (PDT)
Date: Wed, 09 Jun 2010 11:28:58 -0700
From: scott@hyperthought.com
To: "iesg@ietf.org" <iesg@ietf.org>, secdir@ietf.org, draft-ietf-behave-dns64.all@tools.ietf.org
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Importance: Normal
X-Priority: 3 (Normal)
X-Type: plain
Message-ID: <1276108138.248491@192.168.2.230>
X-Mailer: webmail8
Subject: [secdir] secdir review of draft-ietf-behave-dns64-09
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Jun 2010 18:28:58 -0000

I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG.  These comments were written primarily for the benefit of the security area directors.  Document editors and WG chairs should treat these comments just like any other last call comments.

This document describes a DNS mechanism that is used with an IPv6/IPv4 translator to enable an IPv6-only client and IPv4-only server to communicate. The document is well-written, and the security considerations seem adequate. I see no issues with this document.

--Scott