Re: Starting WGLC on draft-ietf-nsis-ntlp-sctp-05.txt
"McDonald, Andrew" <[email protected]>
| Newsgroups | gmane.ietf.nsis |
|---|---|
| Message-ID | <[email protected]> |
Martin Stiemerling wrote: > We start the WGLC on > > draft-ietf-nsis-ntlp-sctp-05.txt > General Internet Signaling Transport (GIST) over SCTP. Mostly looks good. However, the definition of the use of DTLS for GIST appears a bit weak. This is picked up in more detail below. Comments: The definition of SendMessage doesn't /exactly/ match the one in the GIST draft, it would be better if it did (since it would avoid any future questions about why it is slightly different). The definition of NetworkNotification doesn't match the one in the GIST draft, which includes NSLPID as the first parameter. I assume this is an oversight (probably caused by a later change to the GIST draft). A security considerations section normally just discusses the security properties of the protocol, rather than actually defining new protocol components. It might be better to have a "Use of DTLS with GIST" section separate from the security considerations. On a similar topic, it might be better for the document to be renamed, e.g. to "GIST over SCTP and DTLS" to flag up the fact that use of DTLS with GIST is defined here. This is particularly relevant since DTLS might be used with some transport other than SCTP in the future. The introduction and overview sections also fail to mention that DTLS use is being defined in this document. The GIST document (section 5.7.3) says of TLS: "Support for this protocol in conjunction with TCP is REQUIRED; ...". Should a similar statement be made about SCTP/DTLS? i.e., if you are implementing SCTP you MUST implement DTLS, or is the fact that TLS is already a MUST in GIST enough to give you /a/ security solution even if not the best solution? It might be useful to explicitly say that "No MA-Protocol-Options are required for DTLS." Recent GIST drafts added quite a bit of text (section 5.7.3) on the use of TLS with regard to TLS versions, ciphersuites, authentication mechanisms and identity checking. The definition of DTLS seems rather thin in comparison. It is probably the case that some of the usage instructions could be included for DTLS by references to the TLS section of the GIST document. It might be useful to note whether TLS (as already defined for GIST) with SCTP is a valid option for an MA protocol stack. I guess it is, but is less desirable for the reasons given in the dtls-for-sctp document. This is particularly needed if TLS is mandatory, but DTLS isn't (see earlier comment). In the IANA considerations it might be useful to provide the actual table entries for IANA to just drop in - comparing to the ones in the GIST draft, the ones there are a bit wordier than just "Forwards-SCTP". Typo: section 3.4: "repeatet" -> "repeated" best regards, Andrew