Éric Vyncke has entered the following ballot position for
draft-ietf-ipsecme-ikev2-mlkem-06: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to 
https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ 
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-mlkem/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------


# Éric Vyncke INT AD comments for draft-ietf-ipsecme-ikev2-mlkem-06
CC @evyncke

Thank you for the work put into this document.

Please find below some blocking DISCUSS points (easy to address), some
non-blocking COMMENT points/nits (replies would be appreciated even if only for
my own education).

I hope that this review helps to improve the document,

Regards,

-éric

Note: this ballot comments follow the Markdown syntax of
https://github.com/mnot/ietf-comments/tree/main, i.e., they can be processed by
a tool to create github issues.

## DISCUSS (blocking)

As noted in
https://datatracker.ietf.org/doc/statement-iesg-handling-ballot-positions-20220121/,
a DISCUSS ballot is a request to have a discussion on the points below; I
really think that the document would be improved with a change here, but can be
convinced otherwise.

### Section 2.2

The "SHOULD" in `If the checks fail, the responder SHOULD send a Notify payload
of type INVALID_SYNTAX as a response to the request from initiator.` misses the
additional guidance per
https://datatracker.ietf.org/doc/statement-iesg-statement-on-clarifying-the-use-of-bcp-14-key-words/
Adding some text about "preventing DoS" could be the guidance (my guess)

The other "SHOULD" in the document have such a guidance.


----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------


## COMMENTS (non-blocking)

### Use of NIST

Please do s/NIST/US NIST/g in all occurence. I note that section 1.1 use "US"
in the expansion of NIST, so, after this occurence "NIST" can stay unchanged.

### Abstract

s/This draft specifies/This *document* specifies/

### Section 1

s/This document describes how ML-KEM [FIPS203] can be used /This document
*specifies* how ML-KEM [FIPS203] can be used / as it is a PS.

### Section 1.1

The curious reader (myself included) would welcome some explanations on the
"shared secret(ss)" as it does not appear to be used in this document.

### Section 1.2

There is no such thing as "network MTU" so s/can exceed the network MTU/can
exceed the *path* MTU/ (as used further in the text)

Later in text s/require two or three *network* IP packets/require two or three
IP packets/ (or even "more than 1 IP packet" as the path MTU can be very small
in IPv4 ...)

### Section 2.2

Same issue: there is no such thing as "network MTU" so s/network MTU/*path* MTU/

### Section 4

Please add an informative reference to
https://www.iana.org/assignments/ikev2-parameters/ikev2-parameters.xhtml#ikev2-parameters-8



_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to