[secdir] Secdir review of draft-murchison-webdav-prefer-14

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Thu, 19 January 2017 12:40 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7B258129499; Thu, 19 Jan 2017 04:40:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.911
X-Spam-Level:
X-Spam-Status: No, score=-2.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=-1, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6jcnB-Tgk3lG; Thu, 19 Jan 2017 04:40:10 -0800 (PST)
Received: from EUR01-HE1-obe.outbound.protection.outlook.com (mail-he1eur01on0089.outbound.protection.outlook.com [104.47.0.89]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5371D129478; Thu, 19 Jan 2017 04:40:10 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector1-arm-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=tHIGuA++3sgRtjEGrd5XTkugVoZiHw08/9L5BHLECME=; b=n+k/ghCqt04YFtUD5eyEb5hVyRtMCXquReavulo6eBaCwmqpM9e94yV5xnFTHlWF98M8LTaqoWeLtpfQfTEx1O4r6PVf6fvVinHdMLMYwc7rV0Ckni65pn4CXBKk6HZc86anO9dEgX4TVHtFNK0JLVl0tKL8oXzEG0G5DxfmYIc=
Received: from HE1PR0802MB2475.eurprd08.prod.outlook.com (10.175.34.148) by HE1PR0802MB2476.eurprd08.prod.outlook.com (10.175.34.149) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.817.10; Thu, 19 Jan 2017 12:40:07 +0000
Received: from HE1PR0802MB2475.eurprd08.prod.outlook.com ([10.175.34.148]) by HE1PR0802MB2475.eurprd08.prod.outlook.com ([10.175.34.148]) with mapi id 15.01.0817.020; Thu, 19 Jan 2017 12:40:07 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: "'secdir@ietf.org'" <secdir@ietf.org>, "'secdir@ietf.org'" <secdir@ietf.org>, "'draft-murchison-webdav-prefer@ietf.org'" <draft-murchison-webdav-prefer@ietf.org>
Thread-Topic: Secdir review of draft-murchison-webdav-prefer-14
Thread-Index: AdJyUMEio00ZkfmaSJaZaPU0A9io3g==
Date: Thu, 19 Jan 2017 12:40:07 +0000
Message-ID: <HE1PR0802MB24753ADDDF08A9D87EB27087FA7E0@HE1PR0802MB2475.eurprd08.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Hannes.Tschofenig@arm.com;
x-originating-ip: [80.92.115.159]
x-ms-office365-filtering-correlation-id: 4303c00e-6496-45c7-a26f-08d440684d02
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001); SRVR:HE1PR0802MB2476;
x-microsoft-exchange-diagnostics: 1; HE1PR0802MB2476; 7:KN+UX/fgqnMAb0iYxbJoU+u2nrrEjT2Q6veurKOOyPaFtzJbwhS9Yh4pO3EFQeuFeIVLNAV4aJgruGdIvjig4KnhbXQ4k7pafASrmfRq9sqvpE1rsyIuXkc6GYYMgTpn8VJEENdIOCAJ2M+piO1XiB4TflB78PkjAo/Z8V+zLKvOVoGH61oF8d9g/mk3VKA70Zam3aQmgqU3xZ2kHXdMbkbuJYYA/tvO4xuUJFdIApsO5TqQj9LCYLZKGF81lLwKvSm8EhJfZr6f3q/vRAOYtcJwukdwCfVdgFytzZt/SSVjIeSHDzVC0Fmj9HllLQjECqygKrVOYw9c9J/MRVB4U0qXR02nUuAK/CSzJw6ZWoS7NTJ3XqzuMt/tpya9nA9lEwJS260VE9RqCPz5Lq3huVaUddgpZnwyV4x/jAKUZagEnjYuxLI1uximx9ThOHnjFh7Cgcvoi4VDDvrrw7Xoig==
x-microsoft-antispam-prvs: <HE1PR0802MB2476B2915EB1E204D8233641FA7E0@HE1PR0802MB2476.eurprd08.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(192374486261705)(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(8121501046)(5005006)(3002001)(10201501046)(6055026)(6041248)(20161123564025)(20161123562025)(20161123555025)(20161123560025)(6072148); SRVR:HE1PR0802MB2476; BCL:0; PCL:0; RULEID:; SRVR:HE1PR0802MB2476;
x-forefront-prvs: 0192E812EC
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(7916002)(39410400002)(39850400002)(39450400003)(39860400002)(39840400002)(199003)(40434004)(189002)(86362001)(101416001)(5890100001)(5660300001)(3660700001)(7736002)(230783001)(3280700002)(54356999)(2900100001)(99286003)(7696004)(38730400001)(55016002)(122556002)(25786008)(6506006)(50986999)(105586002)(92566002)(6436002)(77096006)(9686003)(8936002)(97736004)(74316002)(6116002)(189998001)(102836003)(106356001)(790700001)(68736007)(33656002)(3846002)(54896002)(5001770100001)(8676002)(81156014)(66066001)(2906002)(6306002)(81166006)(450100001)(53936002)(107886002)(491001); DIR:OUT; SFP:1101; SCL:1; SRVR:HE1PR0802MB2476; H:HE1PR0802MB2475.eurprd08.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_HE1PR0802MB24753ADDDF08A9D87EB27087FA7E0HE1PR0802MB2475_"
MIME-Version: 1.0
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Jan 2017 12:40:07.7406 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0802MB2476
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/cX1mufBL_YyPC5ES6FOPILxD8E8>
Subject: [secdir] Secdir review of draft-murchison-webdav-prefer-14
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Jan 2017 12:40:13 -0000

I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG.  These comments were written primarily for the benefit of the security area directors.  Document editors and WG chairs should treat these comments just like any other last call comments.



The document defines an update to the HTTP Prefer header field to specify how it can be used by a WebDAV client.



This document is Ready.


The security consideration section of this document refers to the security consideration section of RFC 7240. RFC 7240 actually does not say much. While this is a bit funny I couldn't find any negative security implications caused by draft-murchison-webdav-prefer-14.


IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.