[secdir] draft-ietf-avtcore-rtcp-green-metadata-08 ietf last call Secdir review

Vincent Roca via Datatracker <noreply@ietf.org> Wed, 17 June 2026 12:45 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: secdir@ietf.org
Delivered-To: secdir@mail2.ietf.org
Received: from [10.244.21.151] (unknown [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id 684ED102B933E; Wed, 17 Jun 2026 05:45:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1781700314; bh=Ga5N1OGcw4m2Ib+xNfz+447iY4oWsu70+8iBjVVGdi4=; h=From:To:Cc:Subject:Reply-To:Date; b=vpViHIxL0BjqVxukmXfz7mooAP+0P1Ho2A3Hv3dNylLTb+673owbXSEitIhn095hS edVJjxiXhDUVwKIesnOs8TMYNMqV8GyZXshkB9kzNvBP0rRbLPGPE1J66gfD0Z3Hd5 7u7+YwFdbiN2wPs4QeGgtP1CuBWUXiTtMq+6s6As=
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Vincent Roca via Datatracker <noreply@ietf.org>
To: secdir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.67.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <178170031411.626419.15699165149665632605@dt-datatracker-f9b87776f-8pmmg>
Date: Wed, 17 Jun 2026 05:45:14 -0700
Message-ID-Hash: X7WVGZABSCDWHXVQIJILC5XWGRY7USV2
X-Message-ID-Hash: X7WVGZABSCDWHXVQIJILC5XWGRY7USV2
X-MailFrom: noreply@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-secdir.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: avt@ietf.org, draft-ietf-avtcore-rtcp-green-metadata.all@ietf.org, last-call@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: Vincent Roca <vincent.roca@inria.fr>
Subject: [secdir] draft-ietf-avtcore-rtcp-green-metadata-08 ietf last call Secdir review
List-Id: Security Area Directorate <secdir.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/k4RxKmoM0CCzYCiQBVHeVQgA3oM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Owner: <mailto:secdir-owner@ietf.org>
List-Post: <mailto:secdir@ietf.org>
List-Subscribe: <mailto:secdir-join@ietf.org>
List-Unsubscribe: <mailto:secdir-leave@ietf.org>

Document: draft-ietf-avtcore-rtcp-green-metadata
Title: RTP Control Protocol (RTCP) Messages for Temporal-Spatial Resolution
Reviewer: Vincent Roca
Review result: Ready

Hello,

I have reviewed this document as part of the security directorate’s ongoing
effort to review all IETF documents being processed by the IESG. These
comments were written primarily for the benefit of the security area
directors. Document editors and WG chairs should treat these comments just
like any other last call comments.

Summary: ready

Globally, this ID looks ready to me.

I only have a small comment: an ID introducing a extension of a given protocol
usually starts its "Security Considerations" section with a link to the
"Security Consideration" section of base RFC it depends on, since what applies
there also applies in general. For instance, RFC 4585 on extended RFC profiles
discusses timing attacks that IMHO also apply here (eg. what happens if a
malicious entity does not follow timing rules of section 4.2.3). Also, RFC 4585
recommends in its "Security Consideration" section that "Senders as well as
receivers SHOULD behave conservatively when observing strange reporting
behavior", whereas no such recommendation is done here.

Regards,   Vincent