Jari Arkko | 30 Dec 2011 08:52

[MEXT] draft-ietf-mext-mip6-tls AD review

I have reviewed this specification. I think it is in good shape and almost ready to move forward. I have some
comments below, please address them in a new revision of the draft. My main comments relate to sequence
numbers, Section 7, and IANA considerations.

> The HAC can be co-located with the HA, or can be an
> independent entity.  For the latter case, communication between HAC
> and HA is not defined by this document.  The Diameter protocol can be
> used between the HA and HAC when the two entities are not collocated.

I'd change the last sentence to: "Such communication could be built on top of AAA protocols such as
Diameter, for instance."

(You can't just use Diameter, you'd have to define a specific way of doing it.)

> The security framework proposed in this document is not intended to
> replace the currently specified architecture which relies on IPsec
> and IKEv2.  It provides an alternative solution which is more optimal
> for certain deployment scenarios.
>

Add to the end:

This and other alternative security models have been considered by the MEXT working group at the IETF, and
it has been decided that the alternative solutions should be published as Experimental RFCs, so that more
implementation and deployment experience with these models can be gathered. The working group may
reconsider the status of the different models in the future, if it becomes clear that one is superior to the others.

>    Mobile IPv6 implementation complexity increases quite dramatically.

I would just say "... complexity increases."
(Continue reading)


Gmane