Skip to main content

Last Call Review of draft-ietf-tokbind-negotiation-10
review-ietf-tokbind-negotiation-10-secdir-lc-orman-2017-11-27-00

Request Review of draft-ietf-tokbind-negotiation
Requested revision No specific revision (document currently at 14)
Type Last Call Review
Team Security Area Directorate (secdir)
Deadline 2017-11-27
Requested 2017-11-13
Authors Andrei Popov , Magnus Nyström , Dirk Balfanz , Adam Langley
I-D last updated 2017-11-27
Completed reviews Genart Last Call review of -10 by Paul Kyzivat (diff)
Secdir Last Call review of -10 by Hilarie Orman (diff)
Opsdir Last Call review of -10 by Will (Shucheng) LIU (diff)
Artart Telechat review of -12 by Matthew A. Miller (diff)
Genart Telechat review of -12 by Paul Kyzivat (diff)
Assignment Reviewer Hilarie Orman
State Completed
Request Last Call review on draft-ietf-tokbind-negotiation by Security Area Directorate Assigned
Reviewed revision 10 (document currently at 14)
Result Ready
Completed 2017-11-27
review-ietf-tokbind-negotiation-10-secdir-lc-orman-2017-11-27-00
Security review of
Transport Layer Security (TLS) Extension for Token Binding Protocol  Negotiation
draft-ietf-tokbind-negotiation-10

Do not be alarmed.  I have reviewed this document as part of the
security directorate's ongoing effort to review all IETF documents
being processed by the IESG.  These comments were written primarily
for the benefit of the security area directors.  Document editors and
WG chairs should treat these comments just like any other last call
comments.

 From the abstract "This document specifies a Transport Layer Security
(TLS) extension for the negotiation of Token Binding protocol version
and key parameters."

Token binding assures that the necessary authentication information
for a TLS channel is bound solely to that one channel.  As a
preliminary to that binding, the two participants must agree on a
protocol version for establishing a token and the key parameters.  The
TLS extension for this negotiation in the HELLO messages is the
subject of the document under review.

The extension seems to me to be necessary, sufficient, secure, and Ready.

Hilarie