Re: [secdir] Secdir review of draft-ietf-softwire-dslite-deployment

"Lee, Yiu" <> Sun, 14 October 2012 21:27 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 4222A21F84F3; Sun, 14 Oct 2012 14:27:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -102.365
X-Spam-Status: No, score=-102.365 tagged_above=-999 required=5 tests=[AWL=-2.865, BAYES_00=-2.599, HOST_EQ_MODEMCABLE=1.368, HTML_MESSAGE=0.001, IP_NOT_FRIENDLY=0.334, MIME_QP_LONG_LINE=1.396, USER_IN_WHITELIST=-100]
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id dAhgJD3dSLuf; Sun, 14 Oct 2012 14:27:33 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id BDFE821F8417; Sun, 14 Oct 2012 14:27:32 -0700 (PDT)
Received: from ([]) by with ESMTP id 97wm3m1.30377001; Sun, 14 Oct 2012 17:20:32 -0400
Received: from ([]) by ([fe80::492e:3fa1:c2ad:e04e%13]) with mapi id 14.02.0318.001; Sun, 14 Oct 2012 17:27:29 -0400
From: "Lee, Yiu" <>
To: Tobias Gondrom <>, "" <>, "" <>, "" <>
Thread-Topic: Secdir review of draft-ietf-softwire-dslite-deployment
Thread-Index: AQHNqkiVs05vQDP67EWEpjdbieLpVJe5UNmA
Date: Sun, 14 Oct 2012 21:27:28 +0000
Message-ID: <>
In-Reply-To: <>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
user-agent: Microsoft-MacOutlook/
x-originating-ip: []
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="B_3433080448_4008840"
MIME-Version: 1.0
X-Mailman-Approved-At: Sun, 14 Oct 2012 14:28:55 -0700
Subject: Re: [secdir] Secdir review of draft-ietf-softwire-dslite-deployment
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Sun, 14 Oct 2012 21:27:34 -0000

Hi Tobias,

Thanks for reviewing the draft. Comments inline:


From:  Tobias Gondrom <>
Date:  Sunday, October 14, 2012 3:47 PM
To:  "" <>rg>, "" <>rg>,
Subject:  Secdir review of draft-ietf-softwire-dslite-deployment
Resent-To:  <>rg>, <>om>,
<>cn>, <>om>,
<>it>, <>om>, "Yiu L.
LEE" <>

I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG.  These
comments were written primarily for the benefit of the security area
directors.  Document editors and WG chairs should treat these comments just
like any other last call comments.

I believe this document (draft-ietf-softwire-dslite-deployment) has an
adequate security considerations section and the main security risks are
sufficiently described for an informational "deployment considerations" RFC.

section 2.6: 
"Internet hosts such as servers must no longer rely solely on IP address to
identify an abused user."
Don't you mean here: "... an abusive user."
and again in the next sentence " identify an abused user..." should be
" identify an abusive user".

[YL] Fixed.

- section 1: Overview
third sentence: first mention of "softwire" may require a reference

[YL] Fixed.

- section 2.5, last paragraph:
s/Depedning on the rate of NAT table changes/Depending on the rate of NAT
table changes

[YL] Fixed.

Best regards, Tobias