Re: SecDir review of draft-ietf-imapapnd-appendlimit-extension
S Moonesamy <[email protected]> Thu, 31 Dec 2015 13:47:42 -0800
| Newsgroups | gmane.ietf.imapext |
|---|---|
| Message-ID | <[email protected]> |
Hi Paul, At 13:36 31-12-2015, Paul Wouters wrote: >This document is Ready > >The document describes an IMAP extension to convey a limit size for >appending to a mailbox. This prevents situations where the clients >upload data only to have it rejected by the server. The security >considerations are therefor limited in scope, as it is more of an >optimization. The only item mentioned in the section is that an >attacker that knows the limit could optimize their attack by sending >better matching sized payloads for a denial-of-service attack, and >servers should disconnect such clients as abusive. I believe that >it correctly covers any new security risks that could arise from this >document's specification. And that this issue is very minor compared >to other DOS attacks possible by malicious clients that can successfully >authenticate against the IMAP server. Thanks for the review. As a note for the authors, there isn't any issue. Regards, S. Moonesamy (as document shepherd) _______________________________________________ imapext mailing list [email protected] https://www.ietf.org/mailman/listinfo/imapext