Last Call Review of draft-pechanec-pkcs11uri-16
review-pechanec-pkcs11uri-16-secdir-lc-atkins-2015-01-02-00
| Request | Review of | draft-pechanec-pkcs11uri |
|---|---|---|
| Requested revision | No specific revision (document currently at 21) | |
| Type | IETF Last Call Review | |
| Team | Security Area Directorate (secdir) | |
| Deadline | 2014-12-29 | |
| Requested | 2014-12-04 | |
| Authors | Jan Pechanec , Darren Moffat | |
| I-D last updated | 2016-09-29 (Latest revision 2015-02-13) | |
| Completed reviews |
Genart IETF Last Call review of -16
by Suresh Krishnan
(diff)
Genart Telechat review of -19 by Suresh Krishnan (diff) Secdir IETF Last Call review of -16 by Derek Atkins (diff) Opsdir IETF Last Call review of -16 by Sarah Banks (diff) |
|
| Assignment | Reviewer | Derek Atkins |
| State | Completed | |
| Request | IETF Last Call review on draft-pechanec-pkcs11uri by Security Area Directorate Assigned | |
| Reviewed revision | 16 (document currently at 21) | |
| Result | Has nits | |
| Completed | 2015-01-02 |
review-pechanec-pkcs11uri-16-secdir-lc-atkins-2015-01-02-00
Hi,
I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG. These comments were written with the intent of improving
security requirements and considerations in IETF drafts. Comments
not addressed in last call may be included in AD reviews during the
IESG review. Document editors and WG chairs should treat these
comments just like any other last call comments.
I believe this document has no issues.
Editorial comments:
In section 1:
A subset of existing PKCS#11 structure members and object attributes
was chosen believed to be sufficient in uniquely identifying a
PKCS#11 token, storage object, or library in a configuration file, on
...
This sentence is not just long but also awkward. The phrase "was
chosen believed to be.." seems to be missing a conjunction and
possibly a verb. Maybe this was meant to be two sentences that got
smushed together?
In section 3.3:
PKCS#11 specification imposes various limitations on the value of
attributes, be it a more restrictive character set for the "serial"
...
I think you need to start this sentence with an article, i.e. "The
PKCS#11 specification imposes..."
(I'll note that I did not validate the ABNF).
Thanks,
-derek
--
Derek Atkins 617-623-3745
derek at ihtfp.com www.ihtfp.com
Computer and Internet Security Consultant