[secdir] Secdir review of draft-ietf-ecrit-data-only-ea-22

Charlie Kaufman <charliekaufman@outlook.com> Tue, 10 March 2020 04:28 UTC

Return-Path: <charliekaufman@outlook.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 15E383A0D32; Mon, 9 Mar 2020 21:28:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=outlook.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id N0pbfS_1g7w1; Mon, 9 Mar 2020 21:28:05 -0700 (PDT)
Received: from NAM11-DM6-obe.outbound.protection.outlook.com (mail-dm6nam11olkn2056.outbound.protection.outlook.com [40.92.19.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4836B3A0F34; Mon, 9 Mar 2020 21:28:00 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=KVyqdYjtRO71OnthCmaVX2YP2mHPMfmtqx7eBsAZYoIaXaFAFLwcPBc6cwQiE3A7O5QpCHxizEFj9ErVZ4BfbjQgvxU6AyasOrFYFBd/bmjHpa08uRLgJTmUnTPyHj+JQMQFOaxeAt8mQDTTe8k2EMLmWf87v9s4V/Ywu3KvXraCX8AOJwmNMKCJNfBrH5qLd0vkbzFarJELIZJkohwH74SX1RWEP1Iuusl6f/O2m3KJTQtSJYhu3R+bwjNZmzK2q9plc18Tz8x7+S0uKolUKX4pr45AAJ8LS5sl+BMZ5tXcshDcXXTAabcH3wIMARqQx6/2u4GJhBb0YoBna3Etxg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;bh=kFWFjiegfaLIt5qGFh+zzF639y5HBcnif9lS+OxTND4=; b=LgnOW4QbP/0ovhJfi6jXodYxdQ5xqSxaXzVQfQNJRcOsF3OzFtUyCDr8124TpLZ3lyQbv2RNhsRiqXE8jjAjxMduH2EUpfXpMteoiLyX9n8ytR8h9lQuMhLaJc7YU3tHGvQKF0tryqS0QL5btzO5zgsaWMxLPa3uUP8xZkvtmy/LdN93P8z672ShYuCQL9oPdRckJv9SlmtOXao3/tMyDO226bZRTMClX+M6eGG9D45+lQNLnE1A8wHhpDpSb33YRBoo6pQgIXir+lQkojlzHAse4/ltJwDHI2ncX1VVFhq2ih8CHDLt/npO+EpZ7Q74PfFNg0IaRt9pzhg9ySxnaw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=outlook.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;bh=kFWFjiegfaLIt5qGFh+zzF639y5HBcnif9lS+OxTND4=; b=iC3QISZ4s2EKMhgufZ+aFJgN8ZxDON4KPruEl1qJBw5yWp5sUXa9P6e9gFtHbh5wOBs10Ul3ZpfUafGbvgAaVzaw+BqOVu4vo7uZK8mQcUTMaJN6bsnaRGlbuclVpc8+bHPpmyN33BpISDEEy7uTU459Dco0pLdEY/xtdZYoaaVzvbMUv/3lxq6fqzGSUn1vSmZojoMkWBBd3QJkP/DvSBN9KOlXMmagWvls0T8Ml+sf4eFyHhBUWYLqU3qLTySgiYXGsK+2Y0MNjf1z9RuMFE36PLybF1O7xpB6KDSGD4ouHTWjoN95KlOULhYbskyFYtJg0Pd5fy3gaxddsoNwXA==
Received: from CO1NAM11FT034.eop-nam11.prod.protection.outlook.com (2a01:111:e400:3861::36) by CO1NAM11HT107.eop-nam11.prod.protection.outlook.com (2a01:111:e400:3861::67) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2793.11; Tue, 10 Mar 2020 04:27:58 +0000
Received: from MWHPR07MB3022.namprd07.prod.outlook.com (2a01:111:e400:3861::38) by CO1NAM11FT034.mail.protection.outlook.com (2a01:111:e400:3861::248) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2793.11 via Frontend Transport; Tue, 10 Mar 2020 04:27:58 +0000
Received: from MWHPR07MB3022.namprd07.prod.outlook.com ([fe80::b8aa:d51:1c05:e5c2]) by MWHPR07MB3022.namprd07.prod.outlook.com ([fe80::b8aa:d51:1c05:e5c2%10]) with mapi id 15.20.2793.013; Tue, 10 Mar 2020 04:27:58 +0000
From: Charlie Kaufman <charliekaufman@outlook.com>
To: "secdir@ietf.org" <secdir@ietf.org>, "iesg@ietf.org" <iesg@ietf.org>, "draft-ietf-ecrit-data-only-ea.all@ietf.org" <draft-ietf-ecrit-data-only-ea.all@ietf.org>
Thread-Topic: Secdir review of draft-ietf-ecrit-data-only-ea-22
Thread-Index: AQHV9pPmrIjEdIT3Qk+swGPwFHA7rQ==
Date: Tue, 10 Mar 2020 04:27:58 +0000
Message-ID: <MWHPR07MB3022095D6C1139A44443BA66DFFF0@MWHPR07MB3022.namprd07.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-incomingtopheadermarker: OriginalChecksum:CC76F32459D47FF11E118C001832DAC2282056CF59A792B753D295692525A0CA; UpperCasedChecksum:758124576CEF65074093FD191F1618DBD234B9C088CA6FA3C68E9330A02BDE56; SizeAsReceived:6842; Count:42
x-tmn: [A8TdHTbd9dwrHbpOozTCKrwsoSP1/NSo]
x-ms-publictraffictype: Email
x-incomingheadercount: 42
x-eopattributedmessage: 0
x-ms-office365-filtering-correlation-id: 0f4aeb4f-f467-4d33-ae97-08d7c4ab69c1
x-ms-traffictypediagnostic: CO1NAM11HT107:
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 1kwMgRo04J3eySSL7m+Hs+qFJyT14g3sdR+c0bLC09Tma3+HZopHriH7sWo0CZ+6C7r8pOQfZl0wWdwNgFC+dhIhMCbtiyml9Kc/BJ6ftky57STXiMnHalkXWP4JH88br3D3cII2Az4euL1M2iGF9G4d+0S5miMDxMPNzok8Y+UwrV0VkhRX4d6hmUnWnedAEuaP7IM7tTpdNjhsyxlGxhA+d9LZz5BHJKsJEk7UVVc=
x-ms-exchange-antispam-messagedata: sMmh5twVYuGvPdn5muh0UCu4rpYmVjvU2VDWn2+Un+dKjbGBAkxAScIhX7JzsdzTTLxGC9T3olOFZ1GHUMUbO/84OxsqIN1GCT5wirqExGEYNSVQs7ZTprR8p3XF3k4a95xqf89XTJNTBca2aaZIrw==
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_MWHPR07MB3022095D6C1139A44443BA66DFFF0MWHPR07MB3022namp_"
MIME-Version: 1.0
X-OriginatorOrg: outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: 0f4aeb4f-f467-4d33-ae97-08d7c4ab69c1
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-originalarrivaltime: 10 Mar 2020 04:27:58.7687 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Internet
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO1NAM11HT107
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/qTmI5AYzOZOiGum6FnwLdRM6xgY>
Subject: [secdir] Secdir review of draft-ietf-ecrit-data-only-ea-22
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Mar 2020 04:28:15 -0000

I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG.  These comments were written primarily for the benefit of the security area directors.  Document editors and WG chairs should treat these comments just like any other last call comments.

This document defines a new MIME type: 'application/EmergencyCallData.cap+xml' for use primarily by sensors to send alert messages to emergency services providers. It also defines a new Emergency Call Data Type: 'cap' in order to embed this data efficiently in a SIP transaction. I saw no new security issues beyond those already noted for the protocols carrying these messages.

I reviewed version 18 of this document last August, and found no security issues then either. I made several editorial suggestions and they have been incorporated in subsequent drafts.

 --Charlie



Sent from Outlook<http://aka.ms/weboutlook>