29 Sep 21:18
Secdir Review of draft-stjohns-sipso-05
From: Sam Hartman <hartmans-ietf <at> mit.edu>
Subject: Secdir Review of draft-stjohns-sipso-05
Newsgroups: gmane.ietf.general
Date: 2008-09-29 19:20:23 GMT
Subject: Secdir Review of draft-stjohns-sipso-05
Newsgroups: gmane.ietf.general
Date: 2008-09-29 19:20:23 GMT
I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. This draft defines an IPV6 option for labeling the sensitivity of packets on trusted networks. The idea is that all of the components that handle these sensitive packets must support this option. Each component that handles a packet in this architecture needs to be trusted to apply appropriate security policy and not to disclose the packet in environments where the packet is outside of the appropriate sensitivity range. summary: This document is basically ready for publication as an informational document. However significant concerns are present if the IESG plans to continue with its current course of publishing on the standards track. Fixing these concerns will require work, but is definitely doable if there is sufficient consensus. process concern: This document is being sponsored as a proposed standard. However as indicated by the last paragraph in section 1 before section 1.1 this document is a follow-on to RFC 1108, which the IETF deprecated and moved to historic. As that paragraph points out, this option has been in *limited deployment* throughout the history of the internet. While this specification does not specifically invoke the language of RFC 2026 regarding applicability statements, I think that the applicability level "limited use" maps well onto the language of section 1 of this draft. It seems that RFC 2026 recommends against(Continue reading)
Mike
RSS Feed