[secdir] Secdir review of draft-ietf-ecrit-held-routing

"Paul Hoffman" <paul.hoffman@vpnc.org> Sun, 24 January 2016 22:53 UTC

Return-Path: <paul.hoffman@vpnc.org>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BB4D01B3448 for <secdir@ietfa.amsl.com>; Sun, 24 Jan 2016 14:53:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.552
X-Spam-Level:
X-Spam-Status: No, score=0.552 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, HELO_MISMATCH_COM=0.553] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id m7ucJQd035Gz for <secdir@ietfa.amsl.com>; Sun, 24 Jan 2016 14:53:23 -0800 (PST)
Received: from hoffman.proper.com (Opus1.Proper.COM [207.182.41.91]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2AAF21B343D for <secdir@ietf.org>; Sun, 24 Jan 2016 14:53:23 -0800 (PST)
Received: from [10.32.60.39] (50-1-98-110.dsl.dynamic.fusionbroadband.com [50.1.98.110]) (authenticated bits=0) by hoffman.proper.com (8.15.2/8.14.9) with ESMTPSA id u0OMrLY0087918 (version=TLSv1 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <secdir@ietf.org>; Sun, 24 Jan 2016 15:53:22 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
X-Authentication-Warning: hoffman.proper.com: Host 50-1-98-110.dsl.dynamic.fusionbroadband.com [50.1.98.110] claimed to be [10.32.60.39]
From: Paul Hoffman <paul.hoffman@vpnc.org>
To: secdir <secdir@ietf.org>
Date: Sun, 24 Jan 2016 14:53:21 -0800
Message-ID: <30D9039D-03F4-451B-9DE5-4EE25BA277C9@vpnc.org>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"
X-Mailer: MailMate (1.9.3r5187)
Archived-At: <http://mailarchive.ietf.org/arch/msg/secdir/SmBXZwKqTuQ7HfGigxx0gCG_UR4>
Subject: [secdir] Secdir review of draft-ietf-ecrit-held-routing
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 24 Jan 2016 22:53:23 -0000

Greetings. This document, "A Routing Request Extension for the HELD 
Protocol", updates the HELD protocol in a way that exposes a bit more 
privacy information than is already passed around in HELD. That is, it 
adds routing information to the location information already passed in 
HELD.

The document's Privacy Considerations section covers the additional 
issues well. The Security Considerations section is a bit stubbish: 
"This document imposes no additional security considerations beyond 
those already described in [RFC5687] and [RFC6155]"; however, I could 
not see anything that should be added.

--Paul Hoffman