Last Call Review of draft-ietf-netconf-tls-
review-ietf-netconf-tls-secdir-lc-turner-2009-03-13-00

Request Review of draft-ietf-netconf-tls
Requested rev. no specific revision (document currently at 07)
Type Last Call Review
Team Security Area Directorate (secdir)
Deadline 2009-03-10
Requested 2009-02-06
Authors Mohamad Badra
Draft last updated 2009-03-13
Completed reviews Secdir Last Call review of -?? by Sean Turner
Assignment Reviewer Sean Turner
State Completed
Review review-ietf-netconf-tls-secdir-lc-turner-2009-03-13
Review completed: 2009-03-13

Review
review-ietf-netconf-tls-secdir-lc-turner-2009-03-13

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the IESG.
These comments were written primarily for the benefit of the security
area directors. Document editors and WG chairs should treat these
comments just like any other last call comments.

I apologize for doing this so late.

This document defines how to use TLS to secure NETCONF exchanges.



I don't have any security issues but I do I have a question about the 


last paragraph in 2.1.  It says that TLS 1.2 MUST be supported and that 


future versions of TLS will also be supported and those mandatory to 


implement algorithms MUST also be supported.  is that also saying that 


an implementation must support all future version of TLS too?




spt