IETF Last Call Review of draft-ietf-lamps-keyusage-crl-validation-03
review-ietf-lamps-keyusage-crl-validation-03-secdir-lc-geater-2025-11-23-00
| Request | Review of | draft-ietf-lamps-keyusage-crl-validation |
|---|---|---|
| Requested revision | No specific revision (document currently at 04) | |
| Type | IETF Last Call Review | |
| Team | Security Area Directorate (secdir) | |
| Deadline | 2025-12-03 | |
| Requested | 2025-11-19 | |
| Authors | Corey Bonnell , Tadahiko Ito , Tomofumi Okubo | |
| I-D last updated | 2026-06-30 (Latest revision 2026-01-06) | |
| Completed reviews |
Secdir IETF Last Call review of -03
by Jon Geater
(diff)
Genart IETF Last Call review of -03 by Roni Even (diff) |
|
| Assignment | Reviewer | Jon Geater |
| State | Completed | |
| Request | IETF Last Call review on draft-ietf-lamps-keyusage-crl-validation by Security Area Directorate Assigned | |
| Posted at | https://mailarchive.ietf.org/arch/msg/secdir/9GaV6shEYmzSQOXxfYRbWuSAR8E | |
| Reviewed revision | 03 (document currently at 04) | |
| Result | Ready | |
| Completed | 2025-11-23 |
review-ietf-lamps-keyusage-crl-validation-03-secdir-lc-geater-2025-11-23-00
I have reviewed version 03 of draft-ietf-lamps-keyusage-crl-validation and consider it ready for publication. The threat it addresses is important and it is a clear improvement over the existing spec. The security considerations include coversage of he important "what if it's too late?" case. It's slightly concerning that such an asymmetry could sneak through the RFC process but IMO that's the nature of V3 complexity among other things. Good that the authors caught it.