Re: [secdir] SecDir review of draft-ietf-anima-grasp-09

Barry Leiba <barryleiba@computer.org> Wed, 08 March 2017 19:29 UTC

Return-Path: <barryleiba.mailing.lists@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EFB5B12955C; Wed, 8 Mar 2017 11:29:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.37
X-Spam-Level:
X-Spam-Status: No, score=-2.37 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.229, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JLKRSvOb95oX; Wed, 8 Mar 2017 11:29:51 -0800 (PST)
Received: from mail-it0-x236.google.com (mail-it0-x236.google.com [IPv6:2607:f8b0:4001:c0b::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 471661293FF; Wed, 8 Mar 2017 11:29:51 -0800 (PST)
Received: by mail-it0-x236.google.com with SMTP id h10so111838066ith.1; Wed, 08 Mar 2017 11:29:51 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc:content-transfer-encoding; bh=+9mcPtruFdzdhcnhmVHhpUu9CsV11dZ3aSJSgdGHTSE=; b=DbLyahh/2INHmT/0peVJwfJ9il70KyNGgn4WUeZ2EUkJT3pPI82ClbNUJBfixKj7Hs CsL2yjk4BbswPysKGNtn6q2c/bojJ+2GvUv2pPEEYUtZYF7Q/YkXfBelTWgngLYM/CTN i1YH/KBD56ozhS+wzzHABOWEWulgP+haSNqCDyJYEWCUM7rBbR2PcrF8cTmeQoilHeIQ A+RL3pLlYKtuadVrq9CdADeGrmTlgJ4eM4V7LT62g6GxylqIoWrINkECKalsmjBKiQQX 1fuhOCtFZjf5DajhhxFpGOWcNCoLTF/TdBbMQSNJtqQcZWSChphaWy1wDYpRDjO60jdi sUVw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc:content-transfer-encoding; bh=+9mcPtruFdzdhcnhmVHhpUu9CsV11dZ3aSJSgdGHTSE=; b=T7d4OCoRncxahPqMdNjFAHf82c+4NTo3ylC4DGbUf04r+H5EE3X9vDBNEYmMPNgTcr WzIe7mg8IOSiGMnbP6AkJqnvjXG5C/8c6i4ninXegAX/wNgrxaEuy4f+GONdoFqTU8kB j+b5Cp/P4buNzklrhM+jmWBGOLsaxToC9jx/0+abKAbNoKCi4SlHAEO/Ljx6OcopGoFk B2pzltq/OwvhCEU9ecXnVAgV8BKtSbjapZOZ+uwalfAYLNS65lm1o6XCpKWFAkSZtY6m /ZROlIsE48FOI+Qt5jeuLPn9oRo0z9ldadxaZsy8kL+bWdqbZMswIV7bM3tYz6gLHTug wY0w==
X-Gm-Message-State: AMke39kKEHvWAkZfiKrKtTgQXkDEs7TdhIBU58Y3mU0Y7TOcFN1c9JQsVaVFeSRmROJ2bmAe5WRoPq8uN5f71A==
X-Received: by 10.107.46.85 with SMTP id i82mr7391114ioo.85.1489001390626; Wed, 08 Mar 2017 11:29:50 -0800 (PST)
MIME-Version: 1.0
Sender: barryleiba.mailing.lists@gmail.com
Received: by 10.107.35.200 with HTTP; Wed, 8 Mar 2017 11:29:50 -0800 (PST)
In-Reply-To: <3529ba25-09af-85dd-92da-aa9d30606bcc@gmail.com>
References: <CALaySJ+rLh9ZBmydm0bG+TBxGK_dB-UmnkeJusd1C-3zMowwHg@mail.gmail.com> <7752607e-ce49-f8f9-7f09-b3e842bc69b9@gmail.com> <3529ba25-09af-85dd-92da-aa9d30606bcc@gmail.com>
From: Barry Leiba <barryleiba@computer.org>
Date: Wed, 08 Mar 2017 14:29:50 -0500
X-Google-Sender-Auth: SuvIRyg6EkpJA3WxKOgEQ2F02vY
Message-ID: <CAC4RtVBPJWDCFFO6uQy7RWGXNfGcRNHYSyCBcA90K2_SZHsm=A@mail.gmail.com>
To: Brian E Carpenter <brian.e.carpenter@gmail.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/IwZ7WMSEd5WNpy4JJAIwbawfJZU>
Cc: draft-ietf-anima-grasp.all@ietf.org, anima@ietf.org, "secdir@ietf.org" <secdir@ietf.org>
Subject: Re: [secdir] SecDir review of draft-ietf-anima-grasp-09
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 08 Mar 2017 19:29:53 -0000

> On UTF-8:
>
>> The other question is whether there are any restrictions on what
>> Unicode characters can be represented.  You make the colon a special
>> character but give no other restrictions, so an objective name could
>> include space characters (and various related Unicode characters such
>> as tab, EN SPACE, ZERO WIDTH SPACE, and ZERO WIDTH NON-JOINER),
>> control characters (FORM FEED, CARRIAGE RETURN, and the like),
>
> Once we specify byte-by-byte comparison, do we need to worry about
> this in a protocol document? If someone is silly enough to
> specify an objective called 'example.org:Недостаточно握 déjà     vu
> ' do we care, in the protocol design?
>
> Personal opinion: we don't need to say anything.

That's probably correct, and I just wanted to be sure y'all had
thought about it -- more whether there'd be an issue with
space-related characters or confusibles than about real non-Latin
languages or pile-of-poo icons.

Thanks for addressing my comments!

Barry