[secdir] review of draft-ietf-enum-iax-05

"Dan Harkins" <dharkins@lounge.org> Fri, 21 August 2009 21:46 UTC

Return-Path: <dharkins@lounge.org>
X-Original-To: secdir@core3.amsl.com
Delivered-To: secdir@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 393A03A6B9D; Fri, 21 Aug 2009 14:46:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.03
X-Spam-Level:
X-Spam-Status: No, score=-6.03 tagged_above=-999 required=5 tests=[AWL=0.235, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aJan8zm14Hip; Fri, 21 Aug 2009 14:46:42 -0700 (PDT)
Received: from colo.trepanning.net (colo.trepanning.net [69.55.226.174]) by core3.amsl.com (Postfix) with ESMTP id 6E9A03A6831; Fri, 21 Aug 2009 14:46:42 -0700 (PDT)
Received: from www.trepanning.net (localhost [127.0.0.1]) by colo.trepanning.net (Postfix) with ESMTP id 2C93010224074; Fri, 21 Aug 2009 14:46:48 -0700 (PDT)
Received: from 216.31.249.246 (SquirrelMail authenticated user dharkins@lounge.org) by www.trepanning.net with HTTP; Fri, 21 Aug 2009 14:46:48 -0700 (PDT)
Message-ID: <5305e23ba28df21e566bb8be04961f80.squirrel@www.trepanning.net>
Date: Fri, 21 Aug 2009 14:46:48 -0700
From: Dan Harkins <dharkins@lounge.org>
To: secdir@ietf.org
User-Agent: SquirrelMail/1.4.14 [SVN]
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
Importance: Normal
Cc: edguy@emcsw.com, iesg@ietf.org, enum-chars@ietf.org
Subject: [secdir] review of draft-ietf-enum-iax-05
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 21 Aug 2009 21:46:43 -0000

  Hello,

  I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written primarily for the benefit of the
security area directors.  Document editors and WG chairs should treat
these comments just like any other last call comments.

  draft-ietf-enum-iax-05 registers the Inter-Asterisk eXchange (IAX)
protocol according to the guidelines specified in ENUM (RFC 3751).
The registration requirements of RFC 3751 specify that a registration
proposal must have a security analysis and this draft says:

     "this Enumservice provides another fact, visible to anyone
      anonymously, that may be harvested and possibly exploited."

While this is correct I think it would be better use to the language of
RFC 3751 section 3.1.3(2) and say something like: "the protocol provides
for disclosure of information that may facilitate an attack or a
violation of user privacy in some way." Also, this draft has a typo in
section 4: RFC 3822 should be RFC 3833. Other than that, I have no
problems with the draft's security considerations.

  regards,

  Dan.