[secdir] secdir review of draft-dijkstra-urn-ogf-06

"Scott G. Kelly" <scott@hyperthought.com> Fri, 19 August 2011 17:26 UTC

Return-Path: <scott@hyperthought.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 320E821F8BA2 for <secdir@ietfa.amsl.com>; Fri, 19 Aug 2011 10:26:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WPhPC9Ai3v0D for <secdir@ietfa.amsl.com>; Fri, 19 Aug 2011 10:26:31 -0700 (PDT)
Received: from smtp112.iad.emailsrvr.com (smtp112.iad.emailsrvr.com [207.97.245.112]) by ietfa.amsl.com (Postfix) with ESMTP id 2B8AD21F8B9E for <secdir@ietf.org>; Fri, 19 Aug 2011 10:26:31 -0700 (PDT)
Received: from localhost (localhost.localdomain [127.0.0.1]) by smtp41.relay.iad1a.emailsrvr.com (SMTP Server) with ESMTP id 6A4482904BE; Fri, 19 Aug 2011 13:27:27 -0400 (EDT)
X-Virus-Scanned: OK
Received: from dynamic11.wm-web.iad.mlsrvr.com (dynamic11.wm-web.iad1a.rsapps.net [192.168.2.218]) by smtp41.relay.iad1a.emailsrvr.com (SMTP Server) with ESMTP id 27748290501; Fri, 19 Aug 2011 13:27:27 -0400 (EDT)
Received: from hyperthought.com (localhost [127.0.0.1]) by dynamic11.wm-web.iad.mlsrvr.com (Postfix) with ESMTP id 11934E00AF; Fri, 19 Aug 2011 13:27:27 -0400 (EDT)
Received: by apps.rackspace.com (Authenticated sender: scott@hyperthought.com, from: scott@hyperthought.com) with HTTP; Fri, 19 Aug 2011 10:27:27 -0700 (PDT)
Date: Fri, 19 Aug 2011 10:27:27 -0700
From: "Scott G. Kelly" <scott@hyperthought.com>
To: "secdir@ietf.org" <secdir@ietf.org>, "iesg@ietf.org" <iesg@ietf.org>, draft-dijkstra-urn-ogf.all@tools.ietf.org
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Importance: Normal
X-Priority: 3 (Normal)
X-Type: plain
Message-ID: <1313774847.06915599@apps.rackspace.com>
X-Mailer: webmail7.0
Subject: [secdir] secdir review of draft-dijkstra-urn-ogf-06
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 19 Aug 2011 17:26:32 -0000

I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG.  These comments were written primarily for the benefit of the security area directors.  Document editors and WG chairs should treat these comments just like any other last call comments.

From the abstract, this document describes a URN namespace for naming persistent resources for the Open Grid Forum. The security considerations section says that there are no additional security considerations beyond those normally associated with use and resolution of URNs in general, and that implementers should check the Open Grid Forum registry/docs before assuming a given identifier is valid or has a certain meaning.

I don't have much experience with URNs and any associated security issues, but this seems reasonable to me. I don't see any other issues with this doc.

--Scott