[secdir] Re: draft-ietf-v6ops-rfc6146-bis-11 telechat Secdir review
Peter Yee <peter@akayla.com> Thu, 06 August 2026 14:05 UTC
Return-Path: <peter@akayla.com>
X-Original-To: secdir@mail2.ietf.org
Delivered-To: secdir@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 200CC124C10B5; Thu, 6 Aug 2026 07:05:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786025106; bh=R0jDcJMIJz6d/hD7fT0cWzEYXCKoXtEEYwB88GbI4AU=; h=Date:Subject:From:To:CC:References:In-Reply-To; b=Ndcc5f+sZ6FNIlNRuWaoUWRpKsdHO6cPEonZrDBqo9TVf0KKEZMM1d0DIFkQLundf 4+f/9jI24jKh0peCZOoP+dKlKKOChjO8cBxFg2M0Wws6BTGijL+G6kG6XRWxMC8qRB 6tKCwRaYgkKdtP5XEwMhMmbrZiUOnPMSuRTyONy0=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.797
X-Spam-Level:
X-Spam-Status: No, score=-2.797 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=akayla.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hHlt04ZRVVp5; Thu, 6 Aug 2026 07:05:05 -0700 (PDT)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4BE2B124C10AD; Thu, 6 Aug 2026 07:05:05 -0700 (PDT)
Received: from mail3.g24.pair.com (localhost [127.0.0.1]) by mail3.g24.pair.com (Postfix) with ESMTP id 14D7D1A19E1; Thu, 6 Aug 2026 10:05:05 -0400 (EDT)
Received: from [192.168.168.225] (server.houseofyee.com [173.8.184.78]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail3.g24.pair.com (Postfix) with ESMTPSA id 2340D1A1C75; Thu, 6 Aug 2026 10:05:04 -0400 (EDT)
User-Agent: Microsoft-MacOutlook/16.111.26071913
Date: Thu, 06 Aug 2026 07:05:01 -0700
From: Peter Yee <peter@akayla.com>
To: "jordi.palet@theipv6company.com" <jordi.palet@theipv6company.com>
Message-ID: <FC083E36-4A43-470C-9296-F9ED39750D9F@akayla.com>
Thread-Topic: draft-ietf-v6ops-rfc6146-bis-11 telechat Secdir review
References: <178598418285.524.805223859846835231@dt-datatracker-559c48c7fb-qkhml> <E8CFCDE5-F73B-476A-9AF9-9D5BBE8B98DC@theipv6company.com>
In-Reply-To: <E8CFCDE5-F73B-476A-9AF9-9D5BBE8B98DC@theipv6company.com>
Mime-version: 1.0
Content-type: multipart/alternative; boundary="B_3868844704_4027834695"
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akayla.com; h=date:subject:from:to:cc:message-id:references:in-reply-to:mime-version:content-type; s=pair-202402141610; bh=XJJXBF+41C0J00u57jNYPOm8WRMg8Q/FRMbrmx0l5vg=; b=o5g6ImBdAK4/uh51xPjfbI9ivttljla5DMpgsHtrlzXVDw5j30oGxLuzAATlrzQBpjUPz542sIDNfiVqY1RxAjiszSwt2wg7qB9H4bmxtCl169bMiE0OQdwfnnPTgrXbDkZ9CRnWfWcsupH93YZOHi2aPj7OTM8HnL5pXo3fsMcBiRCNHfS+KLZyb3cer1jUTjGM2mQVNFEEFXyukVp+/JgVvlXV8Bjh2JsVY3zE2OhB037PvlpqQOQCyR6vUsoiRp01Ku2yFuvXGE0VKdqN64IKogY7CJ1mHfiA5jXXWKIAPOgE8I61nffILkvUTFB6ajILQkGSXLAGvokMeOSpvg==
X-Scanned-By: mailmunge 3.09 on 66.39.134.11
Message-ID-Hash: AL22LE3766K25MUPOV2KOGF3RIFZFPVY
X-Message-ID-Hash: AL22LE3766K25MUPOV2KOGF3RIFZFPVY
X-MailFrom: peter@akayla.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-secdir.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: secdir@ietf.org, draft-ietf-v6ops-rfc6146-bis.all@ietf.org, last-call@ietf.org, v6ops@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [secdir] Re: draft-ietf-v6ops-rfc6146-bis-11 telechat Secdir review
List-Id: Security Area Directorate <secdir.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/hf2gDvyZQj19h60BLMkcWWwxAcQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Owner: <mailto:secdir-owner@ietf.org>
List-Post: <mailto:secdir@ietf.org>
List-Subscribe: <mailto:secdir-join@ietf.org>
List-Unsubscribe: <mailto:secdir-leave@ietf.org>
Hi, Jordi,
Thank you for considering my comments. Responses inline below.
Kind regards,
-Peter
On 8/6/26, 1:18 AM, "jordi.palet@theipv6company.com" <jordi.palet@theipv6company.com> wrote:
Hi Peter,
Tks a lot for the review.
See below in-line. Corrections will be in v13.
Regards,
Jordi
@jordipalet
El 6 ago 2026, a las 4:43, Peter Yee via Datatracker <noreply@ietf.org> escribió:
Document: draft-ietf-v6ops-rfc6146-bis
Title: Stateful NAT64: Network Address and Protocol Translation from IPv6
Clients to IPv4 Servers Reviewer: Peter Yee Review result: Has Nits
This draft is update to RFC 6146, which deals with NAT64. I didn't find there
to be any security concerns that weren't already handled by the existing
Security Considerations. The addition of the DNSSEC consideration was helpful.
There are a few nits that could be handled, but nothing major. [Ready with Nits]
Major concerns: None
Minor concerns: None
Nits:
General:
Change "behaviour" to "behavior" since most of the other language usage in the
document is American English.
Actually, what happened is that trying to improve the document I passed it thru a couple of spell checkers, and I noticed that we have most of the text as British English, so I decided to change the rest. I’m not sure now if there is any explicit IETF recommendation about using British or American, as I’m in Europe, I tend to use British. Anyway, I’m very confused because for example, even word, tell me that all is correct using British English.
If you can point me to anything specific I will make sure to double check with dictionaries or whatever, happy to change all back to American English if needed. In the worst case, I think this is something that can be fixed with the RFC Editor.
PY> I’m completely fine with either spelling and am only looking for consistency. I’m thinking of things like “synthesize”, “synthesizing”, “summarize”, “summarized”, and “maximize”. My understanding is that British English tends to use “ise” instead of “ize”.
There are a lot cases where "stateful NAT64 translator" is used without an
article ("the" or "a"). I started to list these, but the list was longer than I
felt worth typing in. Consider adding articles. Also, once (in Section 8.2) the
I’m going to fix that during the morning. I checked it, but seems missed some.
PY> There are times when “Stateful NAT64 translator” without an article works. Perhaps the RFC Editor will adjust things.
name "stateful NAT64 translator function" was used. Perhaps drop "function" to
go along with rest of the usage in the document.
I assume you're checking v11, as I think I corrected it already in v12. Will re-check now.
PY>Indeed, I reviewed v11. Seems like you’ve made extensive changes.
There are a few cases where the serial comma is not used (although mostly it
is). Search for "TCP and" or "TCP or" and append a comma after "TCP" to catch
most of them.
Corrected!
PY> Thank you!
Specific:
Page 5, 1st paragraph: change "preceding paragraph" to "preceding bulleted
list".
Done
Page 5, 2nd paragraph, 2nd sentence: insert "some" before "new".
Done
Page 6, 2nd bullet item: append a comma after "e.g.".
Done
Page 13, "Filtering, Address-Dependent", 3rd sentence: change "for receiving"
to "to receive".
Done
Page 21, 2nd bullet item: insert "itself" before "from".
I believe you mean this text (looking not into v12)?
- The stateful NAT64 translator MUST limit the amount of
resources devoted to the storage of fragmented packets in order
to protect itself from DoS attacks.
Page 22, section 3.5, 2nd sentence: change "May" to "It may”.
Done
**********************************************
IPv4 is over
Are you ready for the new Internet ?
http://www.theipv6company.com
The IPv6 Company
This electronic message contains information which may be privileged or confidential. The information is intended to be for the exclusive use of the individual(s) named above and further non-explicilty authorized disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited and will be considered a criminal offense. If you are not the intended recipient be aware that any disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited, will be considered a criminal offense, so you must reply to the original sender to inform about this communication and delete it.
- [secdir] draft-ietf-v6ops-rfc6146-bis-11 telechat… Peter Yee via Datatracker
- [secdir] Re: draft-ietf-v6ops-rfc6146-bis-11 tele… jordi.palet@theipv6company.com
- [secdir] Re: draft-ietf-v6ops-rfc6146-bis-11 tele… jordi.palet@theipv6company.com
- [secdir] Re: draft-ietf-v6ops-rfc6146-bis-11 tele… Peter Yee
- [secdir] Re: draft-ietf-v6ops-rfc6146-bis-11 tele… jordi.palet@theipv6company.com
- [secdir] Re: draft-ietf-v6ops-rfc6146-bis-11 tele… Peter Yee