Re: [Uta] updated I-Ds

"Orit Levin (LCA)" <oritl@microsoft.com> Sun, 23 February 2014 12:18 UTC

Return-Path: <oritl@microsoft.com>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA2E81A0097 for <uta@ietfa.amsl.com>; Sun, 23 Feb 2014 04:18:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.602
X-Spam-Level:
X-Spam-Status: No, score=-2.602 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AN2-tsOLNFIS for <uta@ietfa.amsl.com>; Sun, 23 Feb 2014 04:18:14 -0800 (PST)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1lp0155.outbound.protection.outlook.com [207.46.163.155]) by ietfa.amsl.com (Postfix) with ESMTP id 9CBE51A009E for <uta@ietf.org>; Sun, 23 Feb 2014 04:18:13 -0800 (PST)
Received: from BL2PR03MB290.namprd03.prod.outlook.com (10.141.68.19) by BL2PR03MB592.namprd03.prod.outlook.com (10.255.109.35) with Microsoft SMTP Server (TLS) id 15.0.883.10; Sun, 23 Feb 2014 12:18:07 +0000
Received: from BL2PR03MB290.namprd03.prod.outlook.com ([10.141.68.19]) by BL2PR03MB290.namprd03.prod.outlook.com ([10.141.68.19]) with mapi id 15.00.0883.010; Sun, 23 Feb 2014 12:18:08 +0000
From: "Orit Levin (LCA)" <oritl@microsoft.com>
To: Peter Saint-Andre <stpeter@stpeter.im>, "uta@ietf.org" <uta@ietf.org>
Thread-Topic: [Uta] updated I-Ds
Thread-Index: AQHPKOyYM81v6EF3MU+PpaV+HLl8EprCtZZg
Date: Sun, 23 Feb 2014 12:18:07 +0000
Message-ID: <eb9cb7890a28424fb2d2bddf9192f8b6@BL2PR03MB290.namprd03.prod.outlook.com>
References: <52FD1424.4080400@stpeter.im>
In-Reply-To: <52FD1424.4080400@stpeter.im>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [81.155.215.86]
x-forefront-prvs: 0131D22242
x-forefront-antispam-report: SFV:NSPM; SFS:(10009001)(6009001)(377454003)(13464003)(199002)(189002)(51704005)(87266001)(69226001)(54316002)(56776001)(83322001)(19580405001)(76482001)(19580395003)(94946001)(85306002)(95416001)(94316002)(86612001)(86362001)(81342001)(87936001)(47736001)(50986001)(47976001)(4396001)(2656002)(95666003)(49866001)(81542001)(93516002)(47446002)(93136001)(74502001)(46102001)(80976001)(31966008)(74662001)(33646001)(54356001)(51856001)(53806001)(74366001)(59766001)(79102001)(15975445006)(81816001)(63696002)(74316001)(81686001)(76576001)(76796001)(76786001)(65816001)(92566001)(66066001)(77982001)(80022001)(90146001)(56816005)(74876001)(74706001)(83072002)(85852003)(24736002); DIR:OUT; SFP:1101; SCL:1; SRVR:BL2PR03MB592; H:BL2PR03MB290.namprd03.prod.outlook.com; CLIP:81.155.215.86; FPR:; MLV:sfv; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
Archived-At: http://mailarchive.ietf.org/arch/msg/uta/AlbFjMKfbPoP_XyCf4P1VXhSiaM
Subject: Re: [Uta] updated I-Ds
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 23 Feb 2014 12:18:17 -0000

Peter et al,
First, thanks a lot for investing the cycles before the deadline.
Inline are my comments and questions for clarification.
Looking forward to having a good discussion next week. Hopefully Yaron and Ralph will be able to join remotely.
Orit.

> -----Original Message-----
> From: Uta [mailto:uta-bounces@ietf.org] On Behalf Of Peter Saint-Andre
> Sent: Thursday, February 13, 2014 10:51 AM
> To: uta@ietf.org
> Subject: [Uta] updated I-Ds
> 
> Yaron, Ralph, and I have updated our respective documents as follows:
> 
> 1. draft-sheffer-uta-tls-attacks is in essence what used to be Section 2
> of draft-sheffer-tls-bcp
> 
[OL] Looks good. My question to the list is to what extent having an RFC listing the known attacks is helpful? Should it include more detailed info for each attack?
What are our expectations from the scope of the intended RFC, who would like to contribute, and in what timeframe?

> 2. draft-sheffer-tls-bcp now focuses primarily on the recommendations
>
[OL] A great start!
A few thoughts and questions that come to mind:
- The title includes both TLS and DTLS. Per our AD's email from a few weeks ago, we should discuss how to proceed.
- It would be helpful to compile a list of additional aspects to be covered under Chapter 3 "Considerations" based on the list feedback and  f2f discussions next week.
- In 4.1 the statement that this document is not a profile in the sense of Sec.9 of RFC5246 is very important. It should be at the very top of the document ;-).
For improved readability, please,  consider to
- Combine 3.3 with 4 in terms of content and style (for example, as "Rationale" where appropriate).
- Keep "Security Considerations" to the minimum and incorporate the current "considerations" under the Recommendations topics
- Number the bullets for easier reference
One specific: In 3.3, "export-level" encryption might be an inappropriate term to be used by a standard, while the length examples are probably outdated.
 
> 3. draft-saintandre-xmpp-tls now mostly points to draft-sheffer-tls-bcp
> 
[OL] I trust your knowledge about TLS with XMPP ;--) My comments are procedural only.
- Where would this draft belong to? To UTA or to XMPP since it is an active WG?
- Section 4.6 Unauthenticated Connections carefully and successfully avoids the "opportunistic encryption" terminology ;-) and introduces its own definitions... still an alignment will be needed  with whatever terminology the community decides to use going forward.

> Please review the document set and let us know how things can be
> improved!
[OL] +1
> 
> https://datatracker.ietf.org/doc/draft-sheffer-uta-tls-attacks/
> 
> https://datatracker.ietf.org/doc/draft-sheffer-tls-bcp/
> 
> https://datatracker.ietf.org/doc/draft-saintandre-xmpp-tls/
> 
> Peter
> 
> --
> Peter Saint-Andre
> https://stpeter.im/
> 
> _______________________________________________
> Uta mailing list
> Uta@ietf.org
> https://www.ietf.org/mailman/listinfo/uta