I am the assigned Gen-ART reviewer for
draft-altman-telnet-starttls-02.txt.

For background on Gen-ART, please see the FAQ at
<http://www.alvestrand.no/ietf/gen/art/gen-art-FAQ.html>.

Please resolve these comments along with any other Last Call comments
you may receive.

Document: draft-altman-telnet-starttls-02.txt
Title: Telnet START-TLS Option
Reviewer: Vijay K. Gurbani <[EMAIL PROTECTED]>
Review Date:  January 8, 2007
IESG Telechat date:  January 18, 2007

This draft is basically ready for publication, but has nits that should
be fixed before publication.

This draft proposes the use of TLS between a telnet server and a
telnet client in order to ensure privacy and integrity of telnet
sessions.

Nits and some discussion points follow:

0) The contents do not have page numbers.

1) In S1, second paragraph,
  s/allowed to access to that/allowed access to that

2) I think that the discussion in the Introduction section will benefit
from a figure; something like this:

            Existing trust relationship
            |                         |
            |         TLS             |
            |       Protected         |
   +---+   \|/ +---+    |     +---+  \|/   +---+
  +---+|-------|   |   \|/    |   |------+----+|
  |   |+       |   |==========|   |      |    |+
  +---+        +---+          +---+      +----+

  Client End   Telnet          Telnet    Server End
  Systems      Client          Server    Systems

3) In S5.1, it is stated at the end of the first paragraph that,
 "The verification SHOULD then continue with a check to see if the
 fully qualified host name which the client connected to appears
 anywhere in the server's subject (DN)."

 What may throw off the uninitiated reader here is the use of the
 phrase "fully qualified host name" above.

 To be unambiguous let me state what I think you mean by the phrase
 above.  I believe you mean that if a client uses a host name of
 "telnet.example.com" to query DNS, and DNS returned
 "host1.example.com" in response to a SRV query, then the
 connection itself is established with the host host1.example.com.
 However, the certificate presented by host1.example.com must
 assert the identity "telnet.example.com", since this was the
 DNS query string.

 If so, consider replacing "fully qualified host name" in the
 paragraph with the phrase "DNS query string" or equivalent.

Thanks.

- vijay
--
Vijay K. Gurbani, Bell Laboratories, Alcatel-Lucent
2701 Lucent Lane, Rm. 9F-546, Lisle, Illinois 60532 (USA)
Email: [EMAIL PROTECTED],bell-labs.com,acm.org}
WWW:   http://www.alcatel-lucent.com/bell-labs

_______________________________________________
Gen-art mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/gen-art

Reply via email to