Skip to main content

Last Call Review of draft-elie-nntp-tls-recommendations-01
review-elie-nntp-tls-recommendations-01-secdir-lc-mandelberg-2016-12-08-00

Request Review of draft-elie-nntp-tls-recommendations
Requested revision No specific revision (document currently at 05)
Type Last Call Review
Team Security Area Directorate (secdir)
Deadline 2016-12-26
Requested 2016-11-28
Authors Julien ÉLIE
I-D last updated 2016-12-08
Completed reviews Secdir Last Call review of -01 by David Mandelberg (diff)
Genart Last Call review of -01 by Jouni Korhonen (diff)
Opsdir Last Call review of -04 by Scott O. Bradner (diff)
Genart Telechat review of -03 by Jouni Korhonen (diff)
Genart Telechat review of -04 by Jouni Korhonen (diff)
Assignment Reviewer David Mandelberg
State Completed
Request Last Call review on draft-elie-nntp-tls-recommendations by Security Area Directorate Assigned
Reviewed revision 01 (document currently at 05)
Result Has nits
Completed 2016-12-08
review-elie-nntp-tls-recommendations-01-secdir-lc-mandelberg-2016-12-08-00
Hi,

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written primarily for the benefit of the
security area directors.  Document editors and WG chairs should treat
these comments just like any other last call comments.

I think this document is ready with nits.

Section 2.4: I think the second to last bullet (about lack of STARTTLS)
should be expanded in scope to say "during any previous connection
within a (possibly configurable) time frame" instead of "during the
previous connection." Otherwise, a human might not see the warning the
first time, and the warning would disappear immediately after that.

-- 
David Eric Mandelberg / dseomn
http://david.mandelberg.org/