Last Call Review of draft-ietf-ace-oscore-profile-11
review-ietf-ace-oscore-profile-11-opsdir-lc-dunbar-2020-07-19-00

Request Review of draft-ietf-ace-oscore-profile
Requested rev. no specific revision (document currently at 13)
Type Last Call Review
Team Ops Directorate (opsdir)
Deadline 2020-07-20
Requested 2020-07-06
Authors Francesca Palombini, Ludwig Seitz, Göran Selander, Martin Gunnarsson
Draft last updated 2020-07-19
Completed reviews Genart Last Call review of -11 by Elwyn Davies (diff)
Opsdir Last Call review of -11 by Linda Dunbar (diff)
Assignment Reviewer Linda Dunbar 
State Completed
Review review-ietf-ace-oscore-profile-11-opsdir-lc-dunbar-2020-07-19
Posted at https://mailarchive.ietf.org/arch/msg/ops-dir/7tNKHp14ia6l_U8nxTLUfirU8rg
Reviewed rev. 11 (document currently at 13)
Review result Has Nits
Review completed: 2020-07-19

Review
review-ietf-ace-oscore-profile-11-opsdir-lc-dunbar-2020-07-19

I have reviewed this document as part of the Ops area directorate's ongoing effort to review all IETF documents being processed by the IESG.  These comments were written primarily for the benefit of the Ops area directors.
Document editors and WG chairs should treat these comments just like any other last call comments.

This document describes how to set specific parameters in using  the Authentication and Authorization for Constrained Environments (ACE) framework [I-D.ietf-ace-oauth-authz]. The document is written clear, except some minor issues: 


 Section 4.1.1 states that Nonce Parameter must be sent from the client to RS. What would be the problem if the client doesn't include the "NONCE"? 

Page 12: It asks RFC editor to validate the numbers listed in Figure 7.  There is no explanation or comments for those values. It will be very difficult for RFC editor to validate. It seems to me there are 4 columns but  I can't understand the meaning of the values under 1st, 2nd, and 3rd columns. 

it is kind of difficult to validate the correctness by just reading through the document.  It would be better to have an implementation report of the proposed "Profile".

 
Best Regards,
 Linda Dunbar