Re: [secdir] Secdir review of draft-hakala-urn-nbn-rfc3188bis-00

Vincent Roca <vincent.roca@inria.fr> Thu, 31 May 2018 08:02 UTC

Return-Path: <vincent.roca@inria.fr>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1CF4F12EBE8; Thu, 31 May 2018 01:02:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level:
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AeEQdce_PUns; Thu, 31 May 2018 01:02:53 -0700 (PDT)
Received: from mail3-relais-sop.national.inria.fr (mail3-relais-sop.national.inria.fr [192.134.164.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F1AE412E8EE; Thu, 31 May 2018 01:02:51 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.49,463,1520895600"; d="scan'208,217";a="267086073"
Received: from unknown (HELO [192.168.16.115]) ([193.55.47.16]) by mail3-relais-sop.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 31 May 2018 10:02:47 +0200
From: Vincent Roca <vincent.roca@inria.fr>
Message-Id: <6875C56D-A978-415B-A98F-BEAF886DE846@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_5ABA35CC-B81B-4E84-B6AD-563D826BCA13"
Mime-Version: 1.0 (Mac OS X Mail 11.3 \(3445.6.18\))
Date: Thu, 31 May 2018 10:02:47 +0200
In-Reply-To: <19fae0b2-55b8-17cd-bb40-33581a936f08@mozilla.com>
Cc: Vincent Roca <vincent.roca@inria.fr>, The IESG <iesg@ietf.org>, secdir@ietf.org, draft-hakala-urn-nbn-rfc3188bis.all@ietf.org
To: Peter Saint-Andre <stpeter@mozilla.com>
References: <623421A0-B3BE-43CA-87AD-9B0AA6EF14F4@inria.fr> <19fae0b2-55b8-17cd-bb40-33581a936f08@mozilla.com>
X-Mailer: Apple Mail (2.3445.6.18)
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/vs9aVtuK2S3k8d-lHyBHmWB62dg>
Subject: Re: [secdir] Secdir review of draft-hakala-urn-nbn-rfc3188bis-00
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 May 2018 08:02:56 -0000

Hello Peter,

> Hi Vincent, thanks for your review. I'm the document shepherd and the
> author is on holiday right now, so I'll reply on a few points.

[..]

>> This document specifies the use of National Bibliography Numbers (NBN)s
>> as a particular URN namespace.
>> The authors explain that "no specific security threats have been
>> identified for NBN-based URNs".
>> The authors also explain that, since this document specifies high level
>> concepts, several security aspects are out of scope.
>> I tend to agree with the authors, although I don't know the domain.
> 
> Would you like to see a bit more explanatory text on these matters?

More explanatory text is always welcome, but as I said, I wouldn’t
object if the doc stays as is.

> Thanks for the review!

You’re welcome.

  Vincent