Discuss (2013-02-06)
This document currently claims to Update RFCs 2812 and 2813, which are IETF stream documents that went through a Last Call. It's not clear it actually does, and that these are meant as "see also". If that's right, I suggest we ask these be removed. If that's not right, and these actually do update those RFCs, we should discuss whether this document is in the correct stream.

Comment (2013-02-06)
I also have concerns about giving this document any status with the port number included until it has been through port number review by the designated experts since this may precipitate a collision in the wild.

(Stephen Farrell) (was Discuss, Yes) No Objection

Comment (2014-01-30)
The authors changed the UPDATEs stuff so the 5742 review is now ok.

Comment (2013-02-06)
Comment (2013-02-05)
Note that if this document had come through the IETF stream I probably would have asked for a bit more information about the certificates:

s2.3.1/2: why only common name what about putting the FQDN/nick in the subject alt extension?

s2.3.1/2: when you say should verify that the certificate validates back to an installed Trust Anchor as in [RFC5280]?

s2.3.2: Should the server also verify the client's cert?

WRT to naming matching should RFC 6125 be followed?