Last Call Review of draft-ietf-rohc-ipsec-extensions-hcoipsec-
review-ietf-rohc-ipsec-extensions-hcoipsec-secdir-lc-atkins-2009-09-23-00
Review
review-ietf-rohc-ipsec-extensions-hcoipsec-secdir-lc-atkins-2009-09-23
Hi,
I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG. These comments were written primarily for the benefit of the
security area directors. Document editors and WG chairs should treat
these comments just like any other last call comments.
Integrating Robust Header Compression (ROHC) with IPsec
(ROHCoIPsec) offers the combined benefits of IP security services
and efficient bandwidth utilization. However, in order to
integrate ROHC with IPsec, extensions to the SPD and SAD are
required. This document describes the IPsec extensions required to
support ROHCoIPsec.
While not a security issue, I believe that you should include the
expansion of ROHC in the Abstract.
I believe the security considerations section adequately provide
guidance for the pitfalls of poor algorithm choice and known traffic
analysis attacks.
-derek
--
Derek Atkins 617-623-3745
derek at ihtfp.com www.ihtfp.com
Computer and Internet Security Consultant