[manet] Deb Cooley's Discuss on draft-ietf-manet-dlep-credit -flow-control-17: (with DISCUSS and COMMENT)
Deb Cooley via Datatracker <[email protected]>
| Newsgroups | gmane.ietf.manet |
|---|---|
| Message-ID | <173851187953.394.9567375122041403807@dt-datatracker-6f7f8bdd64-25rl2> |
Deb Cooley has entered the following ballot position for draft-ietf-manet-dlep-credit-flow-control-17: Discuss When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ for more information about how to handle DISCUSS and COMMENT positions. The document, along with other ballot positions, can be found here: https://datatracker.ietf.org/doc/draft-ietf-manet-dlep-credit-flow-control/ ---------------------------------------------------------------------- DISCUSS: ---------------------------------------------------------------------- Please note that this discuss applies to the traffic classification draft, and perhaps to the other two DLEP drafts on the telechat. I would be happy to have them all addressed together, at the authors discretion. Section 4: The transport layer security recommendations in RFC8175 are largely outdated (it predates TLS1.3, RFC8446). It references RFC 7525 (which has been obsoleted by RFC 9325) and RFC 5487 which may/may not be relevant today (i.e. it is very old - predating both TLS 1.2, RFC 5746, and TLS1.3). In addition, the link layer security recommendations are similarily outdated. Please address this issue in this draft's Security Considerations. Section 4: I would also like to see documentation of the risk of 'leaking data' into unused (and unvalidated by the receiver) protocol fields. ---------------------------------------------------------------------- COMMENT: ---------------------------------------------------------------------- Section 2, paragraph 6: Wildcards are mentioned here, but no where else in the draft. Specifically, which packet types listed in this draft can have wildcards specified? Sections 2.3.1, 2.3.3, 2.3.4: Reserved field, why doesn't the router/modem have to validate this (it allows a covert channel if not validated)? _______________________________________________ manet mailing list -- [email protected] To unsubscribe send an email to [email protected]