Skip to main content

IETF Last Call Review of draft-ietf-httpbis-incremental-03
review-ietf-httpbis-incremental-03-secdir-lc-lonvick-2025-12-06-00

Request Review of draft-ietf-httpbis-incremental
Requested revision No specific revision (document currently at 04)
Type IETF Last Call Review
Team Security Area Directorate (secdir)
Deadline 2025-12-16
Requested 2025-12-02
Authors Kazuho Oku , Tommy Pauly , Martin Thomson
I-D last updated 2026-05-20 (Latest revision 2026-03-02)
Completed reviews Genart IETF Last Call review of -03 by Stewart Bryant (diff)
Artart IETF Last Call review of -03 by Julian Reschke (diff)
Secdir IETF Last Call review of -03 by Chris M. Lonvick (diff)
Opsdir IETF Last Call review of -03 by Tina Tsou (Ting ZOU) (diff)
Assignment Reviewer Chris M. Lonvick
State Completed
Request IETF Last Call review on draft-ietf-httpbis-incremental by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/ddYuLzQl9EujOH7U3aBiV4shXIA
Reviewed revision 03 (document currently at 04)
Result Has nits
Completed 2025-12-06
review-ietf-httpbis-incremental-03-secdir-lc-lonvick-2025-12-06-00
Hi,

I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG. These comments
were written primarily for the benefit of the security area directors. Document
editors and WG chairs should treat these comments just like any other last call
comments.

The summary of the review is Ready with Nits.

Overall, the document is readable and understandable. The nit that I found is
that the document says that the implementation of the Increment field is
"advisory" (bottom of page 3) even thought this is a Standards Track document.
I believe that the authors are trying to say that implementation and deployment
will take some time and that not all intermediaries will be provisioned
immediately. If that is the case, the authors may want to consider something
like the following:

>>> It is expected that there will be a transition period while implementations
of the >>> Incremental header field are being deployed in intermediate devices.
During that >>> transition period, an intermediate that cannot interpret the
Incremental header >>> field MUST ignore it. While this is not optimal, that
operation has expected >>> outcomes. However, an intermediate that can
interpret the Incremental header field >>> MUST honor it as described within
this specification.

It may also be good to reference the Security Considerations of [HTTP] and
provide the advice that implementors of Incremental be familiar with that.

Best regards,
Chris