Last Call Review of draft-roach-sip-http-subscribe-

Request Review of draft-roach-sip-http-subscribe
Requested rev. no specific revision (document currently at 07)
Type Last Call Review
Team Security Area Directorate (secdir)
Deadline 2010-02-14
Requested 2010-01-09
Authors Adam Roach
Draft last updated 2010-01-31
Completed reviews Secdir Last Call review of -?? by Tina Tsou
Assignment Reviewer Tina Tsou 
State Completed
Review review-roach-sip-http-subscribe-secdir-lc-tsou-2010-01-31
Review completed: 2010-01-31


I have reviewed this document as part of the
security directorate's ongoing effort to review all IETF documents
being processed by the IESG.  These comments were written primarily
for the benefit of the security area directors.  Document editors and
WG chairs should treat these comments just like any other last call

Comments follow:

1) It is possible that the message/http NOTIFY message bodies may  

contain sensitive information. This is related to the statement at the  

end of the existing Security Considerations text that care should be  

taken to apply the same controls over access to entity information to  

SIP/SIPS subscribers as to users using other protocols. Additional  

text in the Security Considerations section should point out that if  

the NOTIFY requests may return sensitive information, that information  

should be protected in transit by, for example, requiring that the  

subscription use SIPS rather than SIP.

2) Along with this, some reference to RFC 5630 might be valuable, both  

to indicate the limitations of SIPS and to indicate how it should be  


B. R.