Re: [secdir] Secdir last call review of draft-ietf-calext-valarm-extensions-04

Ken Murchison <murch@fastmail.com> Wed, 10 February 2021 13:20 UTC

Return-Path: <murch@fastmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 55D353A0FD2; Wed, 10 Feb 2021 05:20:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.119
X-Spam-Level:
X-Spam-Status: No, score=-2.119 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, NICE_REPLY_A=-0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fastmail.com header.b=Q/vZ8yUx; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=voR+P45E
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rHwGhHWT-2PF; Wed, 10 Feb 2021 05:20:49 -0800 (PST)
Received: from out5-smtp.messagingengine.com (out5-smtp.messagingengine.com [66.111.4.29]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9CBD93A0FCF; Wed, 10 Feb 2021 05:20:49 -0800 (PST)
Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id 5BF8F5C0207; Wed, 10 Feb 2021 08:20:48 -0500 (EST)
Received: from mailfrontend2 ([10.202.2.163]) by compute3.internal (MEProxy); Wed, 10 Feb 2021 08:20:48 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fastmail.com; h= subject:from:to:cc:references:message-id:date:mime-version :in-reply-to:content-type; s=fm2; bh=lkeE1/ScwmCaRjT1G9twD85TiS7 s/dUkFBfymlXutYk=; b=Q/vZ8yUxK+/gIJENuj2vBPoQTpJBXSL3/y2cYexgrU6 BtL5fRo5fbKZTj6l8rGxDuRgLSj7oBGWfrn8/OCVlY3U9dM5EduI5iLMUzNKT+t4 /Z3xz+led4tzOkHM0ZLqxo4HpsdbvdwVvQq1fEESUsuyPftLtbZK4DP9mSWPrjBc WwK0rTxWWnTdJbUnoIBHhz28MkIhBvoVQ+hRzDbTlH4JHMntER4YEMqHl9kRzN4l 2swZubwTRnUXkX8z8DuR5JCkVoQYloBvdV5AeDKcLIIqcawd7AlpjdEEZaQ0ITTl yExtnbfFWtLrEya93cZtjzpyercH9G4iGUGbhqrhr9A==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; bh=lkeE1/ ScwmCaRjT1G9twD85TiS7s/dUkFBfymlXutYk=; b=voR+P45EAlo3rWb5jfci8e IpSk6lVOI74AsO/LUEo/XC9ubN4A4Xhq0B06kpxdZN5Vp6KjllmL18+PLY6EwvQv n+T5iF2ZCJVcorPLQsOFQ03LQaTF4jxYtu9MF8MjUtPXZxnxYsKnGy5y3+jWXSOj bZf87m0CdXOZRxC6Dxmc3PKEKp6aqgE45xgiWC8tFf7PuXQ84udr03wsF4yYhJtr q9w+t0zyhAYROGGU6iml4jXqquebQqtas0ftC9Fxln+esDoEf6jQK+S6AP61DNTQ 0ns0Ey6vs0ke5vftoaApiOP+9btzpYKPqd/q4Qq1Clyp/+5DY6gMreBJP9EwO+pA ==
X-ME-Sender: <xms:r90jYOpOjpIdrDXIUGqvZycWgawhsXDFq1ddxIgV1bNxK56jBaSU-Q> <xme:r90jYMrxKzVb3qBLGE0AM2DKPh39Ak0tSsVXx3UT_ewh1z_LvmTBOxjNHb0IPRDMw oIsPAVT2IfEuQ>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrheejgdehudcutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenuc fjughrpefuhffvfhfkffgfgggjtgesrgdtreertdefjeenucfhrhhomhepmfgvnhcuofhu rhgthhhishhonhcuoehmuhhrtghhsehfrghsthhmrghilhdrtghomheqnecuggftrfgrth htvghrnhepvdefueejffdukedtfffhjeejtdffudejhfdvkeeujeffjeevgeekffelgefg vddvnecuffhomhgrihhnpehivghtfhdrohhrghenucfkphepjeegrdejjedrkeehrddvhe dtnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepmhhu rhgthhesfhgrshhtmhgrihhlrdgtohhm
X-ME-Proxy: <xmx:r90jYDPHiShp3degBWLUwyv8XdXKqOnLvFR9qczvdZ7ZEO8o4wzVkg> <xmx:r90jYN4OiS18hO_QmAz0xIsC_bUDwTTgxLNagbTsRcp0Hk1fbQn9Tg> <xmx:r90jYN6MovvSK49ClmZN95SG19YlCV0aAu2ZNkDRmseL8Ymw9brvJA> <xmx:sN0jYNEXU2C0WwLQm74I5WiKS3eu8pbPf4jAhUelbu9ghPHFA6pw9A>
Received: from [192.168.1.22] (cpe-74-77-85-250.buffalo.res.rr.com [74.77.85.250]) by mail.messagingengine.com (Postfix) with ESMTPA id 837A9108006B; Wed, 10 Feb 2021 08:20:47 -0500 (EST)
From: Ken Murchison <murch@fastmail.com>
To: Valery Smyslov <valery@smyslov.net>, secdir@ietf.org
Cc: calsify@ietf.org, draft-ietf-calext-valarm-extensions.all@ietf.org, last-call@ietf.org
References: <161296108746.13523.4234835837695144328@ietfa.amsl.com> <c244b012-3ecb-95b6-fec4-b8ebec3086e2@fastmail.com>
Message-ID: <c3b99101-d778-4012-8910-f3a10e086d19@fastmail.com>
Date: Wed, 10 Feb 2021 08:20:47 -0500
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.7.0
MIME-Version: 1.0
In-Reply-To: <c244b012-3ecb-95b6-fec4-b8ebec3086e2@fastmail.com>
Content-Type: multipart/alternative; boundary="------------97990FC17170505E4241F062"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/KSRKZZmDhrGvCplXMZl9U_6YfkE>
Subject: Re: [secdir] Secdir last call review of draft-ietf-calext-valarm-extensions-04
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Feb 2021 13:20:53 -0000

On 2/10/21 8:18 AM, Ken Murchison wrote:
>
> Hi Valery,
>
> Thank you for the review.  Per your recommendation, I have added the 
> following phrase to the beginning of the Security Considerations section:
>
> "In addition to the security properties of iCalendar (see Section of 
> [RFC5545] 
> <https://xml2rfc.tools.ietf.org/cgi-bin/xml2rfc.cgi#RFC5545>), ..."
>
Copy and paste error above: this should say "Section 7 of"


> Is this sufficient, or do you have alternative text that you'd like to 
> see?
>
>
> On 2/10/21 7:44 AM, Valery Smyslov via Datatracker wrote:
>> Reviewer: Valery Smyslov
>> Review result: Ready
>>
>> I have reviewed this document as part of the security directorate's ongoing
>> effort to review all IETF documents being processed by the IESG.  These
>> comments were written primarily for the benefit of the security area directors.
>> Document editors and WG chairs should treat these comments just like any other
>> last call comments.
>>
>> The draft defines a set of extensions to the VALARM component of iCalendar.
>> The document is short and well written, its Security Considerations and Privacy Considerations
>> sections are sensible. I found the document ready.
>>
>> Nit: I would recommend adding a sentence to the Security Considerations section saying that
>> these VALARM extensions inherited security properties of iCalendar [RFC5545].
>>
>>
>>
> -- 
> Kenneth Murchison
> Senior Software Developer
> Fastmail US LLC

-- 
Kenneth Murchison
Senior Software Developer
Fastmail US LLC