[secdir] Secdir last call review of draft-ietf-httpbis-client-cert-field-05

Loganaden Velvindron via Datatracker <noreply@ietf.org> Sun, 05 March 2023 18:51 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: secdir@ietf.org
Delivered-To: secdir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 3C35EC151B15; Sun, 5 Mar 2023 10:51:10 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Loganaden Velvindron via Datatracker <noreply@ietf.org>
To: secdir@ietf.org
Cc: draft-ietf-httpbis-client-cert-field.all@ietf.org, ietf-http-wg@w3.org, last-call@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 9.13.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <167804227023.47095.18172427609385674001@ietfa.amsl.com>
Reply-To: Loganaden Velvindron <loganaden@gmail.com>
Date: Sun, 05 Mar 2023 10:51:10 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/xA3ToXmgyHklh-ipGwhbqArXQ7s>
Subject: [secdir] Secdir last call review of draft-ietf-httpbis-client-cert-field-05
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.39
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 05 Mar 2023 18:51:10 -0000

Reviewer: Loganaden Velvindron
Review result: Has Nits

The I-D looks good.

However, I'm slightly confused about the terminology used in section 3.1
3.1.  Header Field Compression

"If the connection between the TTRP and origin is capable of field
   compression (e.g., HPACK [HPACK] or QPACK [QPACK]), and the TTRP
   multiplexes more than one client's requests into that connection, the
   size and variation of Client-Cert and Client-Cert-Chain field values
   can reduce compression efficiency significantly."

Do the authors mean origin server ?