[Joel M. Halpern] Gen-Art LC Review: draft-ietf-kink-kink-11.txt

Sam Hartman <[email protected]> Sat, 10 Dec 2005 17:13:12 -0500
Newsgroups gmane.ietf.kink
Message-ID <[email protected]>
--=-=-=




Hi.  I believe this review is on track and the
intent of the WG was probably to allow kink_encrypt to be used in these situations.
Can people confirm that's the case?

If so, does someone want to suggest a small set of textual changes
that accomplish this?  Please propose changes in rfc-editor note
format (rfcdiff --ab-dif) so we don't need to respin the draft.

--Sam



--=-=-=
Content-Type: message/rfc822
Content-Disposition: inline

Return-Path: <[email protected]>
Received: from solipsist-nation ([unix socket])
	by solipsist-nation (Cyrus v2.1.16-IPv6-Debian-2.1.16-10) with LMTP; Sat,
 10 Dec 2005 16:46:02 -0500
X-Sieve: CMU Sieve 2.2
Return-Path: <[email protected]>
Received: from south-station-annex.mit.edu (SOUTH-STATION-ANNEX.MIT.EDU
 [18.72.1.2])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by suchdamage.org (Postfix) with ESMTP id E817B138AA
	for <[email protected]>; Sat, 10 Dec 2005 16:45:58 -0500 (EST)
Received: from pacific-carrier-annex.mit.edu (PACIFIC-CARRIER-ANNEX.MIT.EDU
 [18.7.21.83])
	by south-station-annex.mit.edu (8.12.4/8.9.2) with ESMTP id jBALjqLG003831
	for <[email protected]>; Sat, 10 Dec 2005 16:45:57 -0500 (EST)
Received: from execdsl.com (mail.shinkuro.com [216.194.124.237])
	by pacific-carrier-annex.mit.edu (8.12.4/8.9.2) with ESMTP id
 jBALgSxf006599
	for <[email protected]>; Sat, 10 Dec 2005 16:42:29 -0500 (EST)
Received: from [71.254.25.204] (HELO JMHLap3.stevecrocker.com)
  by execdsl.com (CommuniGate Pro SMTP 4.2.7)
  with ESMTP id 12826891; Sat, 10 Dec 2005 14:40:18 -0700
Message-Id: <[email protected]>
X-Mailer: QUALCOMM Windows Eudora Version 6.2.1.2
Date: Sat, 10 Dec 2005 16:42:22 -0500
To: <[email protected]>
From: "Joel M. Halpern" <[email protected]>
Subject: Gen-Art LC Review: draft-ietf-kink-kink-11.txt
Cc: Sam Hartman <[email protected]>, [email protected],
	Derek Atkins <[email protected]>,
	Jonathan Trostle <[email protected]>,
	[email protected], [email protected],
	[email protected], [email protected]
In-Reply-To: <[email protected]
 tel.com>
References: <E3F9D87C63E2774390FE67C924EC99BB0AB3D497@zrc2hxm1.corp.nortel.com>
X-Scanned-By: MIMEDefang 2.42
X-Spam-Checker-Version: SpamAssassin 3.0.2 (2004-11-16) on 
	solipsist-nation.suchdamage.org
X-Spam-Level: 
X-Spam-Status: No, score=-1.4 required=5.0 tests=BAYES_00,FORGED_RCVD_HELO 
	autolearn=ham version=3.0.2
MIME-Version: 1.0

I was selected as General Area Review Team reviewer for this specification
(for background on Gen-ART, please see
http://www.alvestrand.no/ietf/gen/art/gen-art-FAQ.html).

This document appears to be ready for publication as a proposed standard.
I do have one minor comment below.  This may be a result of the fact that I 
am not a security expert and may well have misread the document.

Minor:
The wording of section 6.1 describing the content of the REPLY message, 
section 6.3 text describing the CREATE message, the example of the CREATE 
sequence, and section 4.2.7 on KINK_ENCRYPT are subtly inconsistent.
a) The description of KINK_ENCRYPT should indicate that the inner types are 
the same as regular KINK types, and that KINK_ENCRYPT is specifically 
intended to be used as a wrapper around other KINK TLVs.
b) The description of the REPLY and CREATE messages should state that 
KINK_ENCRYPT is a valid TLV.  The wording lists a set of TLVs that are 
valid, and does not list KINK_ENCRYPT.

Yours,
Joel M. Halpern

[Multiple copies of comment sent according to gen-art procedures.]

----
SEC: Kerberized Internet Negotiation of Keys (KINK)
      draft-ietf-kink-kink-11.txt

Responsible AD: Sam Hartman
Reviewer: Joel Halpern



--=-=-=--