[secdir] Secdir last call review of draft-ietf-mile-xmpp-grid-09
Matthew Miller <linuxwolf+ietf@outer-planes.net> Wed, 23 January 2019 18:01 UTC
Return-Path: <linuxwolf+ietf@outer-planes.net>
X-Original-To: secdir@ietf.org
Delivered-To: secdir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 6BFDC1311CE; Wed, 23 Jan 2019 10:01:39 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Matthew Miller <linuxwolf+ietf@outer-planes.net>
To: secdir@ietf.org
Cc: mile@ietf.org, draft-ietf-mile-xmpp-grid.all@ietf.org, ietf@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.90.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <154826649938.7505.11018194912932133243@ietfa.amsl.com>
Date: Wed, 23 Jan 2019 10:01:39 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/u8wCxALUUTWGIPhjT-XGhhMP88Y>
Subject: [secdir] Secdir last call review of draft-ietf-mile-xmpp-grid-09
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jan 2019 18:01:39 -0000
Reviewer: Matthew Miller Review result: Has Issues I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. Document: draft-ietf-mile-xmpp-grid-09 Reviewer: Matthew A. Miller Review Date: 2018-01-23 IETF LC End Date: 2019-01-14 IESG Telechat date: 2019-01-24 Summary: This document defines an architecture for distributing security information using publish-subscribe semantics over XMPP. It is well written and addressed many (but not all) known concerns of a publish-subscribe This document has issues that should be addressed before it is ready to be published as a Proposed Standard. Major Issues: The document does not explicitly discuss the implications of the Controller and Broker having plaintext access and control of the published data. It seems to be implied in the section 8.2.3 for the Controller (and, for those proficient with XMPP, the Broker). I am not strongly recommending any sort of end-to-end protections be proscribed (since existing protections are likely unsuitable for this architecture). The document does not have any real discussion around persistence of node items. if they are expected or desired to be persisted, then there should be some discussion about retention policies (meaning: deployments ought to have one), and behaviors when a Platform subscribes to the Topic (e.g., should or may automatically send the last published item to the recent subscriber). If not, then some discussion on the implications of existing/historic data being unavailable through this mechanism. Minor Issues: XMPP pubsub is complex, and node configuration reflects that. Relying on XEP-0060 is something of a disservice to implementers, in my opinion. I suggest that an addition Topic creation example be added that demonstrates the recommended configuration: * pubsub#access-authorize or access-whitelist * pubsub#persist_items = ?? (1 or 0) * pubsub#send_last_published_item = ?? (on_sub? never?) Nits: N/A
- [secdir] Secdir last call review of draft-ietf-mi… Matthew Miller
- Re: [secdir] Secdir last call review of draft-iet… Nancy Cam-Winget (ncamwing)
- Re: [secdir] Secdir last call review of draft-iet… Peter Saint-Andre
- Re: [secdir] Secdir last call review of draft-iet… Matthew Miller