[kitten] Jari Arkko's Discuss on draft-ietf-kitten-pkinit-freshness-07: (with DISCUSS and COMMENT)

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[kitten] Jari Arkko's Discuss on draft-ietf-kitten-pkinit-freshness-07: (with DISCUSS and COMMENT)

Jari Arkko-2
Jari Arkko has entered the following ballot position for
draft-ietf-kitten-pkinit-freshness-07: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-kitten-pkinit-freshness/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------

I am concerned about the issue that Russ Housley raised in his Gen-ART
review: bad practices in creating the freshness tokens creates a security
issue. If this cannot be handled in the way that Russ initially suggested
(setting a minimum number of bits) then a proper discussion of the issue
and recommendations to avoid the problems need to be included in the
security considerations section.


----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Other issues from Russ' Gen-ART review should also be addressed
(editorial ones + possible max size).


_______________________________________________
Kitten mailing list
[hidden email]
https://www.ietf.org/mailman/listinfo/kitten