Re: Starting WGLC on draft-ietf-nsis-ntlp-sctp-05.txt
Xiaoming Fu <[email protected]>
| Newsgroups | gmane.ietf.nsis |
|---|---|
| Organization | University of Goettingen, Germany |
| Message-ID | <[email protected]> |
Hi Andrew, Thanks for your very constructive hcomments. See my comments below: McDonald, Andrew wrote: > Martin Stiemerling wrote: >> We start the WGLC on >> draft-ietf-nsis-ntlp-sctp-05.txt >> General Internet Signaling Transport (GIST) over SCTP. > > Mostly looks good. However, the definition of the use of DTLS for GIST > appears a bit weak. This is picked up in more detail below. > > Comments: > > The definition of SendMessage doesn't /exactly/ match the one in the > GIST draft, it would be better if it did (since it would avoid any > future questions about why it is slightly different). > > The definition of NetworkNotification doesn't match the one in the GIST > draft, which includes NSLPID as the first parameter. I assume this is an > oversight (probably caused by a later change to the GIST draft). We will readjust both, actually by removing the definition for both APIs. Rather, we would just add a note mentioning the slightly changed (e.g., Timeout) semantic. > > A security considerations section normally just discusses the security > properties of the protocol, rather than actually defining new protocol > components. It might be better to have a "Use of DTLS with GIST" section > separate from the security considerations. You're right. We could add a new separate section to clarify this in the new version. > > On a similar topic, it might be better for the document to be renamed, > e.g. to "GIST over SCTP and DTLS" to flag up the fact that use of DTLS > with GIST is defined here. This is particularly relevant since DTLS > might be used with some transport other than SCTP in the future. The > introduction and overview sections also fail to mention that DTLS use is > being defined in this document. Changing the title sounds good to me (and given DTLS part as additional feature/section). > > The GIST document (section 5.7.3) says of TLS: "Support for this > protocol in conjunction with TCP is REQUIRED; ...". Should a similar > statement be made about SCTP/DTLS? i.e., if you are implementing SCTP > you MUST implement DTLS, or is the fact that TLS is already a MUST in > GIST enough to give you /a/ security solution even if not the best > solution? DTLS: What about: DTLS MUST be implemented and MAY be enabled in an SCTP implementation. Concerning TLS: Due to the past discussions in the WG list and IETF meetings, it is agreeable for the WG not to take TLS as the secure version for GIST/SCTP, hence we choose to avoid mandating the use of TLS over SCTP/GIST. Anyway, TLS is already mandatory to be implemented for GIST/TCP. TLS: What about: TLS MAY be used for securing GIST/SCTP when PR-SCTP is not used. > It might be useful to explicitly say that "No MA-Protocol-Options are > required for DTLS." Ok. > > Recent GIST drafts added quite a bit of text (section 5.7.3) on the use > of TLS with regard to TLS versions, ciphersuites, authentication > mechanisms and identity checking. The definition of DTLS seems rather > thin in comparison. It is probably the case that some of the usage > instructions could be included for DTLS by references to the TLS section > of the GIST document. Yes, will try to take some text/reference from TLS description from GIST spec. > > It might be useful to note whether TLS (as already defined for GIST) > with SCTP is a valid option for an MA protocol stack. I guess it is, but > is less desirable for the reasons given in the dtls-for-sctp document. > This is particularly needed if TLS is mandatory, but DTLS isn't (see > earlier comment). I think there is a WG consensus (correct me if I'm wrong) here as mentioned in my above comments: - use of TLS is optional for GIST/SCTP (when no PR-SCTP is supported) - implementation of DTLS is mandatory and the use is optional for a GIST/SCTP implementation. > > In the IANA considerations it might be useful to provide the actual > table entries for IANA to just drop in - comparing to the ones in the > GIST draft, the ones there are a bit wordier than just "Forwards-SCTP". Right. Will address. > > Typo: > section 3.4: "repeatet" -> "repeated" Noted. Thanks for your feedbacks again! Cheers, Xiaoming > > best regards, > > Andrew > _______________________________________________ > nsis mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/nsis