Deb Cooley has entered the following ballot position for
draft-ietf-dnsop-ds-automation-08: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to 
https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ 
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-dnsop-ds-automation/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thanks to Donald Eastlake for their secdir reviews.

I'm making this a no obj ballot, but I would like it to be carefully
considered. I'm happy to chat about it, if that makes it easier.

Classically for Security Considerations, one would reference a RFC (or I-D)
that outlines the existing pitfalls and issues. Outside of the security area
drafts, a normal draft doesn't put these considerations throughout the draft. 
However, we are not opposed to this idea.

In the author's response to the secdir review, the
draft-ietf-dnsop-cds-consistency was mentioned as covering this concern.  Upon
review, it appears that this draft is referenced in Sections 4.1, 4.2.1, 4.2.3
(and Appendix A.1, which I assume is merely informative).  This assumes that
there are no security considerations for any of the other sections, such as
Section 4.2.2, Section 5 (can notifications be spoofed?), Section 6 or Section
7.  Is this true?

It would be simpler (for both the authors and the readers), if the security
considerations were all in one place.  The authors can reference the
appropriate pre-existing RFC/I-D which keeps the current draft short and to the
point, focused on the operational concerns.



_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to