Last Call Review of draft-elie-nntp-tls-recommendations-01
review-elie-nntp-tls-recommendations-01-secdir-lc-mandelberg-2016-12-08-00

Request Review of draft-elie-nntp-tls-recommendations
Requested rev. no specific revision (document currently at 05)
Type Last Call Review
Team Security Area Directorate (secdir)
Deadline 2016-12-26
Requested 2016-11-28
Draft last updated 2016-12-08
Completed reviews Secdir Last Call review of -01 by David Mandelberg (diff)
Genart Last Call review of -01 by Jouni Korhonen (diff)
Opsdir Last Call review of -04 by Scott Bradner (diff)
Genart Telechat review of -03 by Jouni Korhonen (diff)
Genart Telechat review of -04 by Jouni Korhonen (diff)
Assignment Reviewer David Mandelberg
State Completed
Review review-elie-nntp-tls-recommendations-01-secdir-lc-mandelberg-2016-12-08
Reviewed rev. 01 (document currently at 05)
Review result Has Nits
Review completed: 2016-12-08

Review
review-elie-nntp-tls-recommendations-01-secdir-lc-mandelberg-2016-12-08

Hi,

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written primarily for the benefit of the
security area directors.  Document editors and WG chairs should treat
these comments just like any other last call comments.

I think this document is ready with nits.

Section 2.4: I think the second to last bullet (about lack of STARTTLS)
should be expanded in scope to say "during any previous connection
within a (possibly configurable) time frame" instead of "during the
previous connection." Otherwise, a human might not see the warning the
first time, and the warning would disappear immediately after that.

-- 
David Eric Mandelberg / dseomn
http://david.mandelberg.org/