Re: SecDir review of draft-ietf-imapapnd-appendlimit-extension

S Moonesamy <[email protected]> Thu, 31 Dec 2015 13:47:42 -0800
Newsgroups gmane.ietf.imapext
Message-ID <[email protected]>
Hi Paul,
At 13:36 31-12-2015, Paul Wouters wrote:
>This document is Ready
>
>The document describes an IMAP extension to convey a limit size for
>appending to a mailbox. This prevents situations where the clients
>upload data only to have it rejected by the server. The security
>considerations are therefor limited in scope, as it is more of an
>optimization. The only item mentioned in the section is that an
>attacker that knows the limit could optimize their attack by sending
>better matching sized payloads for a denial-of-service attack, and
>servers should disconnect such clients as abusive. I believe that
>it correctly covers any new security risks that could arise from this
>document's specification. And that this issue is very minor compared
>to other DOS attacks possible by malicious clients that can successfully
>authenticate against the IMAP server.

Thanks for the review.

As a note for the authors, there isn't any issue.

Regards,
S. Moonesamy (as document shepherd) 

_______________________________________________
imapext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/imapext