Last Call Review of draft-ietf-tls-oldversions-deprecate-09
review-ietf-tls-oldversions-deprecate-09-secdir-lc-montville-2020-11-23-00

Request Review of draft-ietf-tls-oldversions-deprecate
Requested rev. no specific revision (document currently at 11)
Type Last Call Review
Team Security Area Directorate (secdir)
Deadline 2020-11-30
Requested 2020-11-09
Authors Kathleen Moriarty, Stephen Farrell
Draft last updated 2020-11-23
Completed reviews Secdir Last Call review of -09 by Adam Montville (diff)
Genart Last Call review of -09 by Mohit Sethi (diff)
Opsdir Last Call review of -09 by Nagendra Nainar (diff)
Assignment Reviewer Adam Montville 
State Completed
Review review-ietf-tls-oldversions-deprecate-09-secdir-lc-montville-2020-11-23
Posted at https://mailarchive.ietf.org/arch/msg/secdir/QUPYWh1FEBderE_LPyr747ea_Ps
Reviewed rev. 09 (document currently at 11)
Review result Ready
Review completed: 2020-11-23

Review
review-ietf-tls-oldversions-deprecate-09-secdir-lc-montville-2020-11-23

I have reviewed this document as part of the security directorate's 
ongoing effort to review all IETF documents being processed by the 
IESG.  These comments were written primarily for the benefit of the 
security area directors.  Document editors and WG chairs should treat 
these comments just like any other last call comments.

The summary of the review is READY.

It's a short, but comprehensive document deprecating use of TLS v1.1 and v1.2, and DTLS v1.0. This deprecation avoids reliance upon weak ciphersuites/cryptographic primitives, and should help focus implementations on a reduced number of requirements (i.e. no fall-back to weak protocols), which ideally results in fewer implementation errors.