Re: [secdir] Secdir telechat review of draft-wilde-service-link-rel-10

Erik Wilde <erik.wilde@dret.net> Fri, 22 March 2019 09:22 UTC

Return-Path: <erik.wilde@dret.net>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1BF4C130EC2; Fri, 22 Mar 2019 02:22:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7JBPu4DtpD6J; Fri, 22 Mar 2019 02:21:59 -0700 (PDT)
Received: from postoffice.gristmillmedia.com (dret.net [209.188.86.86]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A67C6130EC1; Fri, 22 Mar 2019 02:21:56 -0700 (PDT)
Received: from 73.10.0.85.dynamic.wline.res.cust.swisscom.ch ([85.0.10.73]:56355 helo=dretpro.home) by postoffice.gristmillmedia.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.91) (envelope-from <erik.wilde@dret.net>) id 1h7GN7-00086O-KA; Fri, 22 Mar 2019 05:21:54 -0400
To: Stefan Santesson <stefan@aaa-sec.com>, secdir@ietf.org
Cc: draft-wilde-service-link-rel.all@ietf.org, ietf@ietf.org
References: <155324623015.23003.17581075186850679270@ietfa.amsl.com>
From: Erik Wilde <erik.wilde@dret.net>
Message-ID: <76e93d92-a580-11a5-62a5-6467fadae52f@dret.net>
Date: Fri, 22 Mar 2019 10:21:51 +0100
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:60.0) Gecko/20100101 Thunderbird/60.6.0
MIME-Version: 1.0
In-Reply-To: <155324623015.23003.17581075186850679270@ietfa.amsl.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - postoffice.gristmillmedia.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - dret.net
X-Get-Message-Sender-Via: postoffice.gristmillmedia.com: authenticated_id: birdhouse@dret.net
X-Authenticated-Sender: postoffice.gristmillmedia.com: birdhouse@dret.net
X-Source:
X-Source-Args:
X-Source-Dir:
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/YFo4r7Ekq6sGzTw2-Z6c4fk1sXw>
Subject: Re: [secdir] Secdir telechat review of draft-wilde-service-link-rel-10
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Mar 2019 09:22:02 -0000

hello stefan.

thanks a lot for the review!

On 2019-03-22 10:17, Stefan Santesson via Datatracker wrote:
> Reviewer: Stefan Santesson
> Review result: Has Nits
> 
> This document seems to be ready and well written. The security considerations
> section seems reasonable.
> 
> However, I do agree with previous review that the requirements language
> boilerplate may be redundant. There are only 2 capital SHOULD requirements in
> the document and they both appear in the security considerations section. None
> of them are referring to things that can be tested for compliance and they
> could both be downgraded to "should".

that sounds reasonable. if everybody agrees on that, i'd be more than 
happy to make this change:

- lowercase the two capitalized requirements.
- remove RFC 2119 and RFC 8174 section and references.

thanks and kind regards,

dret.

-- 
erik wilde | mailto:erik.wilde@dret.net |
            | http://dret.net/netdret    |
            | http://twitter.com/dret    |