Re: Starting WGLC on draft-ietf-nsis-ntlp-sctp-05.txt

"McDonald, Andrew" <[email protected]>
Newsgroups gmane.ietf.nsis
Message-ID <[email protected]>
Martin Stiemerling wrote:
> We start the WGLC on 
> 
>        draft-ietf-nsis-ntlp-sctp-05.txt
>  General Internet Signaling Transport (GIST) over SCTP. 

Mostly looks good. However, the definition of the use of DTLS for GIST 
appears a bit weak. This is picked up in more detail below.

Comments:

The definition of SendMessage doesn't /exactly/ match the one in the 
GIST draft, it would be better if it did (since it would avoid any 
future questions about why it is slightly different).

The definition of NetworkNotification doesn't match the one in the GIST 
draft, which includes NSLPID as the first parameter. I assume this is an 
oversight (probably caused by a later change to the GIST draft).

A security considerations section normally just discusses the security 
properties of the protocol, rather than actually defining new protocol 
components. It might be better to have a "Use of DTLS with GIST" 
section separate from the security considerations.

On a similar topic, it might be better for the document to be renamed, 
e.g. to "GIST over SCTP and DTLS" to flag up the fact that use of DTLS 
with GIST is defined here. This is particularly relevant since DTLS 
might be used with some transport other than SCTP in the future. The 
introduction and overview sections also fail to mention that DTLS use is 
being defined in this document.

The GIST document (section 5.7.3) says of TLS: "Support for this 
protocol in conjunction with TCP is REQUIRED; ...". Should a similar 
statement be made about SCTP/DTLS? i.e., if you are implementing SCTP 
you MUST implement DTLS, or is the fact that TLS is already a MUST in 
GIST enough to give you /a/ security solution even if not the best solution?

It might be useful to explicitly say that "No MA-Protocol-Options are 
required for DTLS."

Recent GIST drafts added quite a bit of text (section 5.7.3) on the use 
of TLS with regard to TLS versions, ciphersuites, authentication 
mechanisms and identity checking. The definition of DTLS seems rather 
thin in comparison. It is probably the case that some of the usage 
instructions could be included for DTLS by references to the TLS section 
of the GIST document.

It might be useful to note whether TLS (as already defined for GIST) 
with SCTP is a valid option for an MA protocol stack. I guess it is, but 
is less desirable for the reasons given in the dtls-for-sctp document. 
This is particularly needed if TLS is mandatory, but DTLS isn't (see 
earlier comment).

In the IANA considerations it might be useful to provide the actual 
table entries for IANA to just drop in - comparing to the ones in the 
GIST draft, the ones there are a bit wordier than just "Forwards-SCTP".

Typo:
section 3.4: "repeatet" -> "repeated"

best regards,

Andrew
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.