[secdir] Re: draft-ietf-v6ops-rfc6146-bis-11 telechat Secdir review

"jordi.palet@theipv6company.com" <jordi.palet@theipv6company.com> Thu, 06 August 2026 13:58 UTC

Return-Path: <prvs=167841d718=jordi.palet@theipv6company.com>
X-Original-To: secdir@mail2.ietf.org
Delivered-To: secdir@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 5F6A6124BED0F; Thu, 6 Aug 2026 06:58:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786024728; bh=/eQ5prpcbuCiPTrxBurapb0r+GCVTuhMw4Jc81FyT/U=; h=From:Subject:Date:In-Reply-To:Cc:To:References; b=VozDaJ1prK1q1SRpCcv2TpKCW6u+k6p7BYiRl/iOyUzOGncv4iTrtrLxy9KcBD8/5 LV6D1OhOss0A+Y3oQMTLMEJUpGP0hdMVW1B/+E3xU5VHgqr4jltc12fjjKPyk3MlFR bocbLHK++kAziQbD5JI/plzBTg+WQ3kH5SyroF4M=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=theipv6company.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ABsOlZf_C5i0; Thu, 6 Aug 2026 06:58:47 -0700 (PDT)
Received: from mail.consulintel.es (mail.consulintel.es [IPv6:2001:470:1f09:495::5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 65F02124BED05; Thu, 6 Aug 2026 06:58:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=theipv6company.com; s=mailer; t=1786024727; x=1786629527; i=jordi.palet@theipv6company.com; q=dns/txt; h=From:Message-Id: Content-Type:Mime-Version:Subject:Date:In-Reply-To:Cc:To: References; bh=SKfnUODZAFk7kHBKDAJgwBtqNUR7xLn9aJ8EXhqnxQw=; b=A 6A4IOYUYvK5sFLywiXnGHgFXANSaDLPMks+bwiD0A3IOrp/xnS7P0ydm8A4GWt0f CMbffNpt1Ds2Msqx4BlWuT547aaDzqhdECHw6kjmF4ojm+q0KHgXM2T+HGMhW6tw XoK3orVZck6UT2FYUFf/QqXo1gFwNa4hGeK2anMPTWT9QjynKk1Lpmo8cKcihEYj yoAT6oQvuwggS7oyDzixxoYigGV2dTF6REYN4fT/RhsKXRXBrhbqEShgqoZDJSOA 622kfdMIM7+J0jD3C9UVVnhmFlXNlg2adBHQH1lbrBRTySAAC1XnRrZSkXd0GCzn 2Jo0ueDFQKrvCrZr3NEkw==
X-MDAV-Processed: mail.consulintel.es, Thu, 06 Aug 2026 15:58:47 +0200 (not processed: message from trusted source)
X-Spam-Processed: mail.consulintel.es, Thu, 06 Aug 2026 15:58:46 +0200
Received: from smtpclient.apple by mail.consulintel.es (127.0.0.1) (MDaemon PRO v25.5.0) with ESMTPSA id md5001002859133.msg; Thu, 06 Aug 2026 15:58:45 +0200
X-MDRemoteIP: 2001:470:1f09:495:6168:ffa6:bd04:d16
X-MDArrival-Date: Thu, 06 Aug 2026 15:58:45 +0200
X-Authenticated-Sender: jordi.palet@theipv6company.com
X-Return-Path: prvs=167841d718=jordi.palet@theipv6company.com
X-Envelope-From: jordi.palet@theipv6company.com
From: "jordi.palet@theipv6company.com" <jordi.palet@theipv6company.com>
Message-Id: <D2DA1692-B1A4-4470-91AE-1F4FB47598F2@theipv6company.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_D21CBD9D-3D3E-41CA-935B-1D754EA3D783"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.700.51.1.1\))
Date: Thu, 06 Aug 2026 15:58:33 +0200
In-Reply-To: <E8CFCDE5-F73B-476A-9AF9-9D5BBE8B98DC@theipv6company.com>
To: Peter Yee <peter@akayla.com>
References: <178598418285.524.805223859846835231@dt-datatracker-559c48c7fb-qkhml> <E8CFCDE5-F73B-476A-9AF9-9D5BBE8B98DC@theipv6company.com>
X-Mailer: Apple Mail (2.3864.700.51.1.1)
X-MDCFSigsAdded: theipv6company.com
Message-ID-Hash: EUGWROBL2BMI7NACX6D7DLEHH4VKCIQQ
X-Message-ID-Hash: EUGWROBL2BMI7NACX6D7DLEHH4VKCIQQ
X-MailFrom: prvs=167841d718=jordi.palet@theipv6company.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-secdir.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: secdir@ietf.org, draft-ietf-v6ops-rfc6146-bis.all@ietf.org, last-call@ietf.org, v6ops@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [secdir] Re: draft-ietf-v6ops-rfc6146-bis-11 telechat Secdir review
List-Id: Security Area Directorate <secdir.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/mswsgnpkD4crSwK6javYZofROuc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Owner: <mailto:secdir-owner@ietf.org>
List-Post: <mailto:secdir@ietf.org>
List-Subscribe: <mailto:secdir-join@ietf.org>
List-Unsubscribe: <mailto:secdir-leave@ietf.org>

Hi Peter,

Just to confirm that did the corrections in the already published v13.

Regards,
Jordi

@jordipalet

> El 6 ago 2026, a las 10:18, jordi.palet@theipv6company.com escribió:
> 
> Hi Peter,
> 
> Tks a lot for the review.
> 
> See below in-line. Corrections will be in v13.
> 
> Regards,
> Jordi
> 
> @jordipalet
> 
>> El 6 ago 2026, a las 4:43, Peter Yee via Datatracker <noreply@ietf.org> escribió:
>> 
>> Document: draft-ietf-v6ops-rfc6146-bis
>> Title: Stateful NAT64: Network Address and Protocol Translation from IPv6
>> Clients to IPv4 Servers Reviewer: Peter Yee Review result: Has Nits
>> 
>> This draft is update to RFC 6146, which deals with NAT64. I didn't find there
>> to be any security concerns that weren't already handled by the existing
>> Security Considerations. The addition of the DNSSEC consideration was helpful.
>> There are a few nits that could be handled, but nothing major. [Ready with Nits]
>> 
>> Major concerns: None
>> 
>> Minor concerns: None
>> 
>> Nits:
>> 
>> General:
>> 
>> Change "behaviour" to "behavior" since most of the other language usage in the
>> document is American English.
> 
> Actually, what happened is that trying to improve the document I passed it thru a couple of spell checkers, and I noticed that we have most of the text as British English, so I decided to change the rest. I’m not sure now if there is any explicit IETF recommendation about using British or American, as I’m in Europe, I tend to use British. Anyway, I’m very confused because for example, even word, tell me that all is correct using British English.
> 
> If you can point me to anything specific I will make sure to double check with dictionaries or whatever, happy to change all back to American English if needed. In the worst case, I think this is something that can be fixed with the RFC Editor.
> 
>> 
>> There are a lot cases where "stateful NAT64 translator" is used without an
>> article ("the" or "a"). I started to list these, but the list was longer than I
>> felt worth typing in. Consider adding articles. Also, once (in Section 8.2) the
> 
> I’m going to fix that during the morning. I checked it, but seems missed some.
> 
>> name "stateful NAT64 translator function" was used. Perhaps drop "function" to
>> go along with rest of the usage in the document.
> 
> I assume you're checking v11, as I think I corrected it already in v12. Will re-check now.
> 
>> 
>> There are a few cases where the serial comma is not used (although mostly it
>> is). Search for "TCP and" or "TCP or" and append a comma after "TCP" to catch
>> most of them.
> 
> Corrected!
> 
>> 
>> Specific:
>> 
>> Page 5, 1st paragraph: change "preceding paragraph" to "preceding bulleted
>> list".
> 
> Done
> 
>> 
>> Page 5, 2nd paragraph, 2nd sentence: insert "some" before "new".
> 
> Done
> 
> 
>> 
>> Page 6, 2nd bullet item: append a comma after "e.g.".
>> 
> 
> Done
> 
>> Page 13, "Filtering, Address-Dependent", 3rd sentence: change "for receiving"
>> to "to receive".
> 
> Done
> 
>> 
>> Page 21, 2nd bullet item: insert "itself" before "from".
> 
> I believe you mean this text (looking not into v12)?
> 
>       -  The stateful NAT64 translator MUST limit the amount of
>          resources devoted to the storage of fragmented packets in order
>          to protect itself from DoS attacks.
> 
> 
>> 
>> Page 22, section 3.5, 2nd sentence: change "May" to "It may”.
>> 
>> 
> 
> Done
> 



**********************************************
IPv4 is over
Are you ready for the new Internet ?
http://www.theipv6company.com
The IPv6 Company

This electronic message contains information which may be privileged or confidential. The information is intended to be for the exclusive use of the individual(s) named above and further non-explicilty authorized disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited and will be considered a criminal offense. If you are not the intended recipient be aware that any disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited, will be considered a criminal offense, so you must reply to the original sender to inform about this communication and delete it.