Re: [secdir] [Last-Call] Secdir last call review of draft-ietf-calext-valarm-extensions-04

Valery Smyslov <smyslov.ietf@gmail.com> Wed, 10 February 2021 13:33 UTC

Return-Path: <smyslov.ietf@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1FCA73A0FED; Wed, 10 Feb 2021 05:33:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BOPIBPxXpe-o; Wed, 10 Feb 2021 05:33:02 -0800 (PST)
Received: from mail-ed1-x529.google.com (mail-ed1-x529.google.com [IPv6:2a00:1450:4864:20::529]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DCEFC3A0FEC; Wed, 10 Feb 2021 05:33:01 -0800 (PST)
Received: by mail-ed1-x529.google.com with SMTP id l12so3020937edt.3; Wed, 10 Feb 2021 05:33:01 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:references:in-reply-to:subject:date:message-id :mime-version:thread-index:content-language; bh=kiYb9XsXypYSW/XSeW0U/9cLZac76nHv4gmLMWNbh3Q=; b=n8VamtSxmLeI4dOjRlIHhT86xTbELfBY6nHEj4SFZUwPIDrxpKehwLnkksFsEgJV6e lOyX6wtECwuu2a5EkWq0v33ucu0u138EuuA1TgOLdxPJs7E+Rd+dpooZaBI8dl3Vvx/F EBsak8YdruVd4FcvNx9qE4vRfBxauD7lEQr2bmrmA9SxJ/KTC5W9u11l8hrQ4bd0IjQg DzekufmAeHVZ9E86nmjZNU3XKbSoh8Al/6rQMEkUbP5bpr7LdS+P1QGFWNaG2XoLkE5+ 4wa+8+13GeBHs1cc3lgJrEOSBM6oQhyiwf9GSorXqhjU3d0XE3Vj0PFUsxGZqQU/xioW lo6A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:references:in-reply-to:subject:date :message-id:mime-version:thread-index:content-language; bh=kiYb9XsXypYSW/XSeW0U/9cLZac76nHv4gmLMWNbh3Q=; b=DcpxIIIq8CssVlZ8RxH8nVQiDlOWyL6KF3GO6wuwEXLOdCEiX7JJFH7aYuoI+UlYSt 6o9diICS0usxKSxZQqJoOam2pALJwh54GwZVzRRqy3uoJhFeOUQK6KBLLTbxl7YfwTOz e1fafeu/rBWIdfJBwL6c9N7E8qiwk3ymMsWdjK9b5xnzb7S4Qt1DL4oMYAsEd5sh+8yJ 5Lsmvi3OZ/EA3cXEbHUehBkNsLz/y+Xqq5FWXSycVB/rYjKqQVU5Vi2tISbM174Juvm4 /3VJjhhV8LB/nL6fpf7+Tx3ged/GV5fS572q4gjL3PcNFMq96m1DaoOh8iJgUQA5XAqa yF5A==
X-Gm-Message-State: AOAM531yy49fzFfU8Gman1HEjeepW9jt7DGpfwKNVcJ7eoLwOK0y03oB bXkMp1Vpc7Hruna7ZZtnP6uPJQuEdbY=
X-Google-Smtp-Source: ABdhPJy6IEUK5fQwbJ1+pb7aWb9bZ1ia/DFatGKGuh6UMQmlvX/XJDwE3jiJkCgmt1qUWdCicoRWBQ==
X-Received: by 2002:a05:6402:1398:: with SMTP id b24mr3050535edv.108.1612963978917; Wed, 10 Feb 2021 05:32:58 -0800 (PST)
Received: from buildpc ([93.188.44.203]) by smtp.gmail.com with ESMTPSA id c3sm1027535edr.94.2021.02.10.05.32.58 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 10 Feb 2021 05:32:58 -0800 (PST)
From: Valery Smyslov <smyslov.ietf@gmail.com>
To: 'Ken Murchison' <murch@fastmail.com>, 'Valery Smyslov' <valery@smyslov.net>, secdir@ietf.org
Cc: last-call@ietf.org, calsify@ietf.org, draft-ietf-calext-valarm-extensions.all@ietf.org
References: <161296108746.13523.4234835837695144328@ietfa.amsl.com> <c244b012-3ecb-95b6-fec4-b8ebec3086e2@fastmail.com>
In-Reply-To: <c244b012-3ecb-95b6-fec4-b8ebec3086e2@fastmail.com>
Date: Wed, 10 Feb 2021 16:33:00 +0300
Message-ID: <03b801d6ffb1$40de67e0$c29b37a0$@gmail.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_03B9_01D6FFCA.662D2680"
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQLTTaZ0+UFogF+cMETFyy7NkxKZ3AJur/63qEVQr2A=
Content-Language: ru
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/whG0HfjbtZUhz-k-sNfmMjpj9mc>
Subject: Re: [secdir] [Last-Call] Secdir last call review of draft-ietf-calext-valarm-extensions-04
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Feb 2021 13:33:04 -0000

Hi Kenneth,

 

I think this addition is OK.

 

Thank you,

Valery.

 

Hi Valery,

Thank you for the review.  Per your recommendation, I have added the following phrase to the beginning of the Security Considerations section:

"In addition to the security properties of iCalendar (see Section of [RFC5545] <https://xml2rfc.tools.ietf.org/cgi-bin/xml2rfc.cgi#RFC5545> ), ..."

Is this sufficient, or do you have alternative text that you'd like to see?

 

On 2/10/21 7:44 AM, Valery Smyslov via Datatracker wrote:

Reviewer: Valery Smyslov
Review result: Ready
 
I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG.  These
comments were written primarily for the benefit of the security area directors.
Document editors and WG chairs should treat these comments just like any other
last call comments.
 
The draft defines a set of extensions to the VALARM component of iCalendar.
The document is short and well written, its Security Considerations and Privacy Considerations
sections are sensible. I found the document ready.
 
Nit: I would recommend adding a sentence to the Security Considerations section saying that 
these VALARM extensions inherited security properties of iCalendar [RFC5545].
 
 
 

-- 
Kenneth Murchison
Senior Software Developer
Fastmail US LLC