Re: [secdir] secdir review of draft-raj-dhc-tftp-addr-option-04

Samuel Weiler <weiler@watson.org> Wed, 03 December 2008 04:41 UTC

Return-Path: <secdir-bounces@ietf.org>
X-Original-To: secdir-archive@ietf.org
Delivered-To: ietfarch-secdir-archive@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id E2D723A69B6; Tue, 2 Dec 2008 20:41:42 -0800 (PST)
X-Original-To: secdir@core3.amsl.com
Delivered-To: secdir@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id C272B3A69B6; Tue, 2 Dec 2008 20:41:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oraxwlOyxgHZ; Tue, 2 Dec 2008 20:41:41 -0800 (PST)
Received: from fledge.watson.org (fledge.watson.org [65.122.17.41]) by core3.amsl.com (Postfix) with ESMTP id 0C46A3A699A; Tue, 2 Dec 2008 20:41:40 -0800 (PST)
Received: from fledge.watson.org (localhost.watson.org [127.0.0.1]) by fledge.watson.org (8.14.3/8.14.2) with ESMTP id mB34fPB0019057; Tue, 2 Dec 2008 23:41:25 -0500 (EST) (envelope-from weiler@watson.org)
Received: from localhost (weiler@localhost) by fledge.watson.org (8.14.3/8.14.2/Submit) with ESMTP id mB34fPE7019053; Tue, 2 Dec 2008 23:41:25 -0500 (EST) (envelope-from weiler@watson.org)
X-Authentication-Warning: fledge.watson.org: weiler owned process doing -bs
Date: Tue, 02 Dec 2008 23:41:25 -0500
From: Samuel Weiler <weiler@watson.org>
To: Jeffrey Hutzelman <jhutz@cmu.edu>
In-Reply-To: <C474E77702BC43C909166102@atlantis.pc.cs.cmu.edu>
Message-ID: <alpine.BSF.1.10.0812022339580.2327@fledge.watson.org>
References: <alpine.BSF.1.10.0811260255330.4213@fledge.watson.org> <90AC45ED-BF49-46ED-A35A-14E1BF699959@cisco.com> <200812022101.mB2L1Ftf002108@raisinbran.srv.cs.cmu.edu> <C474E77702BC43C909166102@atlantis.pc.cs.cmu.edu>
User-Agent: Alpine 1.10 (BSF 962 2008-03-14)
MIME-Version: 1.0
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.0 (fledge.watson.org [127.0.0.1]); Tue, 02 Dec 2008 23:41:26 -0500 (EST)
Cc: Richard Johnson <raj@cisco.com>, IETF Discussion <ietf@ietf.org>, secdir@ietf.org, Ralph Droms <rdroms@cisco.com>, dhc Chairs <dhc-chairs@tools.ietf.org>, IESG IESG <iesg@ietf.org>, John C Klensin <john-ietf@jck.com>
Subject: Re: [secdir] secdir review of draft-raj-dhc-tftp-addr-option-04
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/pipermail/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="us-ascii"; Format="flowed"
Sender: secdir-bounces@ietf.org
Errors-To: secdir-bounces@ietf.org

On Tue, 2 Dec 2008, Jeffrey Hutzelman wrote:

>> It seems to me that there is a middle ground here.   One can
>> stick with Informational publication as the WG intends, but
>> still modify the Security Considerations section, not only to
>> remove the reference to option 66 (if there is consensus that is
>> appropriate) but to add some explanation about why the use of
>> this option without authentication might be problematic.
...
> I'm inclined to agree with John here.

Likewise.

And thank you for providing the clarification on how widely this 
option is used.  Given that date, I withdraw the suggestion that the 
doc not be published.

-- Sam

_______________________________________________
secdir mailing list
secdir@ietf.org
https://www.ietf.org/mailman/listinfo/secdir