Skip to main content

IETF Last Call Review of draft-deshpande-secevent-http-multi-set-push-03
review-deshpande-secevent-http-multi-set-push-03-secdir-lc-kelly-2026-08-29-00

Request Review of draft-deshpande-secevent-http-multi-set-push
Requested revision No specific revision (document currently at 03)
Type IETF Last Call Review
Team Security Area Directorate (secdir)
Deadline 2026-09-23
Requested 2026-08-26
Authors Apoorva Deshpande , Aaron Parecki
I-D last updated 2026-08-26 (Latest revision 2026-08-24)
Completed reviews Httpdir Early review of -00 by Darrel Miller (diff)
Genart Early review of -00 by Russ Housley (diff)
Secdir Early review of -00 by Scott G. Kelly (diff)
Secdir IETF Last Call review of -03 by Scott G. Kelly
Assignment Reviewer Scott G. Kelly
State Completed
Request IETF Last Call review on draft-deshpande-secevent-http-multi-set-push by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/3DgeYE4AO7wB0zw3MVsSeqUMJt4
Reviewed revision 03
Result Ready
Completed 2026-08-29
review-deshpande-secevent-http-multi-set-push-03-secdir-lc-kelly-2026-08-29-00
I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG. These comments
were written primarily for the benefit of the security area directors. Document
editors and WG chairs should treat these comments just like any other last call
comments. The summary of the review is ready.

From the abstract, this specification defines how multiple Security Event
Tokens (SETs) can be delivered to an intended recipient using HTTP POST over
TLS. At the end of the introduction, the doc says “This specification will
handle all the use cases and scenarios for the [RFC8935] and make it more
extensible to support multiple SETs per one outbound POST request.” So, I’m
assuming that this doc is extending RFC8935 to support multiple SETs.

The security considerations section starts with “The Security Considerations of
[RFC8935], [RFC9846], and Section 17 of [RFC9110] apply to this specification.”

Section 17 of RFC9110 is the Security Considerations section of that doc, so I
would suggest changing this to say “The Security Considerations of [RFC8935],
[RFC9846], and [RFC9110] apply to this specification.”

I think the security considerations section does a good job and covers what it
should. It does cover a few things I naively thought must be covered by 8935,
but after double-checking, I think this document adds some important
clarifications. I don’t have any suggestions for improvements.