All: This is a partial review of draft-ietf-stir-rfc4474bis-15 that I am
sending out in time for Gen-ART representation during the
teleconference.

No showstoppers so far, and I don't expect any.

I will send out the complete review today with the required template.

Apologies for the straddled review.

Thanks.

Minor:
- S3: "baseline SIP" ==> What do you mean by this?  (I know what you
 mean, of course, but others reading the document may not.)  Perhaps
 the following substitution is better?

 s/purposes of baseline SIP,/use of SIP as defined in [RFC 3261],/

Nits:

- S1: "However, the recipient of a SIP request has no way to verify
 that the From header field has been populated appropriately, in the
 absence of some sort of cryptographic authentication mechanism."
 Changing the order of the dependent clauses may lead to better
 readability.  That is,
 "However, in the absence of some sort of cryptographic authentication
 mechanism, the recipient of a SIP request has no way to verify that
 the From header field has been populated appropriately."

- S1: You may want to define what "swatting" is for those not well-
 versed in ART terminology.

- S1: "less spoofable" ... Merriam-Webster does not define "spoofable"
 as a word (online version).  Perhaps better to say "less amenable to
 spoofing" instead.  Something as the following suggested text:
 "Ideally, a cryptographic approach to identity can provide a much
 stronger assurance of identity than the Caller ID service used
 by the public-switched telephone network today.  Such an approach
 would also be less amenable to identity spoofing."

- S3: s/through means entirely up to the authentication service,/through
  per-arranged means with the authentication service,/

- S3: s/credentials that will be trusted by relying parties to sign for
 telephone numbers are a key component of the architecture./credentials
 that will be trusted by relying parties to be authoritative for
 telephone numbers become a key component of the architecture./

- S3: s/not so easy to/not as easy to/

- S3: s/ but this document does not mandate or specify a credential
 system.  [I-D.ietf-stir-certificates] describes a credential system
 compatible with this architecture./ but this document does not mandate
 or specify a particular credential system;
 [I-D.ietf-stir-certificates] describes one credential system compatible
 with this architecture."

- S3 s/This is typically easier to deal with, as these identities are
 issued to users by authorities over Internet domains./This is
 typically easier to deal with as these identities are issued by
 organizations that have authority over Internet domains./

- S3: s/can issue them an identity/issues an identity/

- S3: s/prove in some fashion/proves/

- vijay
--
Vijay K. Gurbani, Bell Laboratories, Nokia Networks
1960 Lucent Lane, Rm. 9C-533, Naperville, Illinois 60563 (USA)
Email: [email protected] / [email protected]
Web: http://ect.bell-labs.com/who/vkg/  | Calendar: http://goo.gl/x3Ogq

_______________________________________________
Gen-art mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/gen-art

Reply via email to