Skip to main content

IETF Last Call Review of draft-ietf-grow-nrtm-v4-08
review-ietf-grow-nrtm-v4-08-secdir-lc-ladd-2026-03-01-00

Request Review of draft-ietf-grow-nrtm-v4
Requested revision No specific revision (document currently at 11)
Type IETF Last Call Review
Team Security Area Directorate (secdir)
Deadline 2026-03-04
Requested 2026-02-18
Authors Sasha Romijn , Job Snijders , Edward Shryane , Stavros Konstantaras
I-D last updated 2026-06-02 (Latest revision 2026-04-17)
Completed reviews Genart IETF Last Call review of -08 by Paul Kyzivat (diff)
Secdir IETF Last Call review of -08 by Watson Ladd (diff)
Httpdir IETF Last Call review of -08 by Julian Reschke (diff)
Opsdir IETF Last Call review of -08 by Menachem Dodge (diff)
Rtgdir IETF Last Call review of -08 by Daniele Ceccarelli (diff)
Artart IETF Last Call review of -08 by Claudio Allocchio (diff)
Assignment Reviewer Watson Ladd
State Completed
Request IETF Last Call review on draft-ietf-grow-nrtm-v4 by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/07RFoNeGo05Eu8tp6-hi5ySQLcU
Reviewed revision 08 (document currently at 11)
Result Has nits
Completed 2026-03-01
review-ietf-grow-nrtm-v4-08-secdir-lc-ladd-2026-03-01-00
Dear all,

I have read this document as part of the SECDIR effort to read all IDs
proceeding to the IESG. These comments should be treated like any other in last
call. A summary of my review is Ready with nits.

The sole substantive comment I have is that the selection of just Elliptic
Curve keys in Section 4.1 is probably too broad and too narrow at the same
time. To broad in that there are many potential noninteroperable or not widely
implemented curves, too narrow in that emerging PQ signatures will need a
document update to be used. It may be worth rethinking mandating this choice
here. Section 4.1 could also use a bit of editing: the server configures a
private key, then this public key is used.

Editorially I think there were a few times I wrinkled my brow when reading due
to forward referencing, but I think the document is short enough this is fine,
and at this stage in the game such a big change as to reorder with the data up
front, and then how the servers get set up to serve it is probably not worth it.

Sincerely,
Watson Ladd