[stir] Martin Duke's No Objection on draft-ietf-stir-cert-delegation-03: (with COMMENT)

Martin Duke via Datatracker <noreply@ietf.org> Mon, 31 August 2020 22:54 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: stir@ietf.org
Delivered-To: stir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id AF3343A05AC; Mon, 31 Aug 2020 15:54:51 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Martin Duke via Datatracker <noreply@ietf.org>
To: "The IESG" <iesg@ietf.org>
Cc: draft-ietf-stir-cert-delegation@ietf.org, stir-chairs@ietf.org, stir@ietf.org, Russ Housley <housley@vigilsec.com>, housley@vigilsec.com
X-Test-IDTracker: no
X-IETF-IDTracker: 7.15.0
Auto-Submitted: auto-generated
Precedence: bulk
Reply-To: Martin Duke <martin.h.duke@gmail.com>
Message-ID: <159891449169.27024.5928128702602857499@ietfa.amsl.com>
Date: Mon, 31 Aug 2020 15:54:51 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/X4fZhcDCsWOGpkTvPA0yQPAWR2Y>
Subject: [stir] Martin Duke's No Objection on draft-ietf-stir-cert-delegation-03: (with COMMENT)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 31 Aug 2020 22:54:53 -0000

Martin Duke has entered the following ballot position for
draft-ietf-stir-cert-delegation-03: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-stir-cert-delegation/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

S/has a own parent/has their own parent

Sec 7. You may want to specify what happens if the PASSporT contains both x5c
and x5u (presumably, ignore the former).

It also says “ The certificate path [RFC5280] ordering MUST be organized from
the trust anchor towards the signer“, which to me, means the trust anchor would
be first. This is the opposite of what the rest of the paragraph says.