[Webpush] Ben Campbell's Yes on draft-ietf-webpush-protocol-11: (with COMMENT)

"Ben Campbell" <ben@nostrum.com> Wed, 12 October 2016 21:25 UTC

Return-Path: <ben@nostrum.com>
X-Original-To: webpush@ietf.org
Delivered-To: webpush@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id C1D0012954F; Wed, 12 Oct 2016 14:25:46 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Ben Campbell <ben@nostrum.com>
To: The IESG <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.34.2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <147630754676.6419.3793529940535426058.idtracker@ietfa.amsl.com>
Date: Wed, 12 Oct 2016 14:25:46 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/webpush/9yxOZ5K1kb5g8hAFMQPPhQIbmSE>
Cc: draft-ietf-webpush-protocol@ietf.org, shida@ntt-at.com, webpush-chairs@ietf.org, webpush@ietf.org
Subject: [Webpush] Ben Campbell's Yes on draft-ietf-webpush-protocol-11: (with COMMENT)
X-BeenThere: webpush@ietf.org
X-Mailman-Version: 2.1.17
List-Id: Discussion of potential IETF work on a web push protocol <webpush.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/webpush>, <mailto:webpush-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/webpush/>
List-Post: <mailto:webpush@ietf.org>
List-Help: <mailto:webpush-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/webpush>, <mailto:webpush-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 12 Oct 2016 21:25:47 -0000

Ben Campbell has entered the following ballot position for
draft-ietf-webpush-protocol-11: Yes

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-webpush-protocol/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thanks for a well written document. I have a few questions on one topic,
for which the answers may be obvious to people other than me:

In section 8, 2nd paragraph: "Applications using this protocol MUST use
mechanisms that provide
   confidentiality, integrity and data origin authentication."

What must it use those mechanisms for? Are we talking about communication
between the UA and app servers? Are we just talking about data in motion?
 As much as I like to see such requirements in general, is it reasonable
for webpush to state requirements on the internal operation of the
application?