IETF Last Call Review of draft-deshpande-secevent-http-multi-set-push-03
review-deshpande-secevent-http-multi-set-push-03-secdir-lc-kelly-2026-08-29-00
| Request | Review of | draft-deshpande-secevent-http-multi-set-push |
|---|---|---|
| Requested revision | No specific revision (document currently at 03) | |
| Type | IETF Last Call Review | |
| Team | Security Area Directorate (secdir) | |
| Deadline | 2026-09-23 | |
| Requested | 2026-08-26 | |
| Authors | Apoorva Deshpande , Aaron Parecki | |
| I-D last updated | 2026-08-26 (Latest revision 2026-08-24) | |
| Completed reviews |
Httpdir Early review of -00
by Darrel Miller
(diff)
Genart Early review of -00 by Russ Housley (diff) Secdir Early review of -00 by Scott G. Kelly (diff) Secdir IETF Last Call review of -03 by Scott G. Kelly |
|
| Assignment | Reviewer | Scott G. Kelly |
| State | Completed | |
| Request | IETF Last Call review on draft-deshpande-secevent-http-multi-set-push by Security Area Directorate Assigned | |
| Posted at | https://mailarchive.ietf.org/arch/msg/secdir/3DgeYE4AO7wB0zw3MVsSeqUMJt4 | |
| Reviewed revision | 03 | |
| Result | Ready | |
| Completed | 2026-08-29 |
review-deshpande-secevent-http-multi-set-push-03-secdir-lc-kelly-2026-08-29-00
I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. The summary of the review is ready. From the abstract, this specification defines how multiple Security Event Tokens (SETs) can be delivered to an intended recipient using HTTP POST over TLS. At the end of the introduction, the doc says “This specification will handle all the use cases and scenarios for the [RFC8935] and make it more extensible to support multiple SETs per one outbound POST request.” So, I’m assuming that this doc is extending RFC8935 to support multiple SETs. The security considerations section starts with “The Security Considerations of [RFC8935], [RFC9846], and Section 17 of [RFC9110] apply to this specification.” Section 17 of RFC9110 is the Security Considerations section of that doc, so I would suggest changing this to say “The Security Considerations of [RFC8935], [RFC9846], and [RFC9110] apply to this specification.” I think the security considerations section does a good job and covers what it should. It does cover a few things I naively thought must be covered by 8935, but after double-checking, I think this document adds some important clarifications. I don’t have any suggestions for improvements.