Kathleen Moriarty has entered the following ballot position for
draft-ietf-homenet-hncp-09: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-homenet-hncp/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------

I have a couple of pints to discuss that should be pretty easy to resolve
as I wasn't clear on the first because of wording (should be very simple)
and would like to chat about the second.  Thanks.

1. I'm not clear on one of the bullets in section 3, 
  o  HNCP nodes MUST use the leading 64 bits of MD5 [RFC1321] as DNCP
      non-cryptographic hash function H(x).

Is this meant to use a message digest (RFC1321) or a cryptographic hash
for authentication (RFC2104)?  If it's the former, can you make this more
clear in the bullet?  If it's the latter, can you update the reference
and the number of bits to use for truncation is 80 for the minimum.  You
do explicitly mention HMACs later on for PSKs using SHA256, so maybe the
reference is correct and the wording should just be a bit more clear?

2. Can you explain why DTLS is a SHOULD and not a MUST?  The bullet in
section 3 reads as if this is for use, not implementation.  Is there a
MUST for implementation (I didn't see one, but maybe I missed that)? 

Could you add a reference to RFC7525 to help with configuration and
cipher suite recommendations?  This could be in section 12, security
considerations.




_______________________________________________
homenet mailing list
homenet@ietf.org
https://www.ietf.org/mailman/listinfo/homenet

Reply via email to