Comments on the Rserpool architecture internet draft -- last call
| Newsgroups | gmane.ietf.rserpool |
|---|---|
| Message-ID | <57A26D272F67A743952F6B4371B8F81101222F27@daebe007.americas.nokia.com> |
There is no security considerations section in the architecture draft. I should have caught this earlier -- my bad! Here is a suggestion: The Rserpool protocol must allow us to secure the Rserpool infrastructure. There are security and privacy issues that relate to the namespace, pool element registration and user queries of the namespace. In [1] a complete threat analysis of Rserpool components is presented. [1] Threats Introduced by Rserpool and Requirements for Security in response to Threats, draft-ietf-rserpool-threats-00.txt, work in progress. This is how it is handled in the OPES architecture document http://www.ietf.org/internet-drafts/draft-ietf-opes-architecture-04.txt. I have some nits, but I'll send them tomorrow. Of course, other suggestions are welcome. -- maureen