Hi Tom,
  Thank you for considering the comments. Please see inline.

Best Regards,
Meral

> -----Original Message-----
> From: Tom Yu [mailto:[email protected]]
> Sent: Friday, December 05, 2014 6:02 PM
> To: Meral Shirazipour
> Cc: [email protected]; [email protected]
> Subject: Re: Gen-ART Last Call review of draft-ietf-kitten-cammac-00
>
> Thank you for your review.  I have written some responses below.
>
> Meral Shirazipour <[email protected]> writes:
>
> > Nits/editorial comments:
>
> > [Page 1], Abstract section, please remove the duplication of the word
> abstract (first word of first sentence).
>
> Thanks; fixed in next revision.
>
> > [Page 1], Abstract, suggestion: the actual motivation should be briefly
> mentioned in the abstract. (e.g. that AD-KDC-ISSUED is not sufficient in cases
> where ...).
>
> I think the motivation is too complicated to concisely summarize in the
> abstract.  We could mention that AD-KDC-ISSUED has known shortcomings
> that will be detailed in the document, if that helps.

I think that would help.

>
> > [Page 3], "The svc-verifier element of the CAMMAC", is svc newly introduced
> in this draft? If so it would be clearer to mention it, e.g. "The new 
> svc-verifier
> element of the CAMMAC"
>
> That paragraph indicates that the svc-verifier element of CAMMAC  takes the
> same role as the ad-checksum element of AD-KDC-ISSUED.  I think it doesn't
> qualify as new in this context.  Please let me know if there is alternative
> wording that would make this more clear.

In that case I would leave as is. Thank you for the clarification.

>
> > [Page 3], same sentence as above, should it be "AD-CAMMAC" instead of
> "CAMMAC" ?
>
> I think of CAMMAC as the abstract concept behind this authorization data,
> and of AD-CAMMAC as the ASN.1 type.  If this usage is confusing, we could
> change to use AD-CAMMAC more consistently throughout.

I think it is best to just use AD-CAMMAC then, or repeat the above explanation 
in the draft.

>
> > [Page 3], "svc-verifier", does svc acronym stand for something? (service and
> the Key Distribution Center ? ) Both svc and should be spelled out at first 
> use.
>
> "svc" is a common abbreviation for "service", but we can expand it on the 
> first
> use if that helps.  KDC is spelled out on its first use in the Introduction.

Yes it would be clearer to do that.

>
> > [Page 6], Section 5, if an Application server does not recognize the
> > AD-CAMMAC container and the latter was not enclosed in the
> > AD-IF-RELEVENT,
> >
> > should the Application server send an error or ignore ?
>
> RFC 4120 specifies that a server receiving unknown authorization data MUST
> fail the authentication process.  Do you think this needs repeating in this
> document?

Yes I think it would be good to mentioned it: "As stated in RFC4120, ..."

_______________________________________________
Gen-art mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/gen-art

Reply via email to