Re: Starting WGLC on draft-ietf-nsis-ntlp-sctp-05.txt

Xiaoming Fu <[email protected]>
Newsgroups gmane.ietf.nsis
Organization University of Goettingen, Germany
Message-ID <[email protected]>
Hi Andrew,

Thanks for your very constructive hcomments. See my comments below:

McDonald, Andrew wrote:
> Martin Stiemerling wrote:
>> We start the WGLC on
>>        draft-ietf-nsis-ntlp-sctp-05.txt
>>  General Internet Signaling Transport (GIST) over SCTP. 
> 
> Mostly looks good. However, the definition of the use of DTLS for GIST 
> appears a bit weak. This is picked up in more detail below.
> 
> Comments:
> 
> The definition of SendMessage doesn't /exactly/ match the one in the 
> GIST draft, it would be better if it did (since it would avoid any 
> future questions about why it is slightly different).
> 
> The definition of NetworkNotification doesn't match the one in the GIST 
> draft, which includes NSLPID as the first parameter. I assume this is an 
> oversight (probably caused by a later change to the GIST draft).

We will readjust both, actually by removing the definition for both 
APIs. Rather, we would just add a note mentioning the slightly changed 
(e.g., Timeout) semantic.

> 
> A security considerations section normally just discusses the security 
> properties of the protocol, rather than actually defining new protocol 
> components. It might be better to have a "Use of DTLS with GIST" section 
> separate from the security considerations.

You're right. We could add a new separate section to clarify this in the 
new version.
> 
> On a similar topic, it might be better for the document to be renamed, 
> e.g. to "GIST over SCTP and DTLS" to flag up the fact that use of DTLS 
> with GIST is defined here. This is particularly relevant since DTLS 
> might be used with some transport other than SCTP in the future. The 
> introduction and overview sections also fail to mention that DTLS use is 
> being defined in this document.

Changing the title sounds good to me (and given DTLS part as additional 
feature/section).

> 
> The GIST document (section 5.7.3) says of TLS: "Support for this 
> protocol in conjunction with TCP is REQUIRED; ...". Should a similar 
> statement be made about SCTP/DTLS? i.e., if you are implementing SCTP 
> you MUST implement DTLS, or is the fact that TLS is already a MUST in 
> GIST enough to give you /a/ security solution even if not the best 
> solution?

DTLS: What about:
DTLS MUST be implemented and MAY be enabled in an SCTP implementation.

Concerning TLS: Due to the past discussions in the WG list and IETF 
meetings, it is agreeable for the WG not to take TLS as the secure 
version for GIST/SCTP, hence we choose to avoid mandating the use of TLS 
over SCTP/GIST.
Anyway, TLS is already mandatory to be implemented for GIST/TCP.

TLS: What about:
TLS MAY be used for securing GIST/SCTP when PR-SCTP is not used.

> It might be useful to explicitly say that "No MA-Protocol-Options are 
> required for DTLS."
Ok.
> 
> Recent GIST drafts added quite a bit of text (section 5.7.3) on the use 
> of TLS with regard to TLS versions, ciphersuites, authentication 
> mechanisms and identity checking. The definition of DTLS seems rather 
> thin in comparison. It is probably the case that some of the usage 
> instructions could be included for DTLS by references to the TLS section 
> of the GIST document.

Yes, will try to take some text/reference from TLS description from GIST 
spec.
> 
> It might be useful to note whether TLS (as already defined for GIST) 
> with SCTP is a valid option for an MA protocol stack. I guess it is, but 
> is less desirable for the reasons given in the dtls-for-sctp document. 
> This is particularly needed if TLS is mandatory, but DTLS isn't (see 
> earlier comment).

I think there is a WG consensus (correct me if I'm wrong) here as 
mentioned in my above comments:
- use of TLS is optional for GIST/SCTP (when no PR-SCTP is supported)
- implementation of DTLS is mandatory and the use is optional for a 
GIST/SCTP implementation.
> 
> In the IANA considerations it might be useful to provide the actual 
> table entries for IANA to just drop in - comparing to the ones in the 
> GIST draft, the ones there are a bit wordier than just "Forwards-SCTP".

Right. Will address.
> 
> Typo:
> section 3.4: "repeatet" -> "repeated"
Noted.

Thanks for your feedbacks again!

Cheers,
Xiaoming
> 
> best regards,
> 
> Andrew
> _______________________________________________
> nsis mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/nsis
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.