Re: [Gen-art] Gen-ART LC Review of draft-ietf-radext-dtls-11

2014-05-01 Thread Jouni
On Apr 30, 2014, at 11:39 PM, Ben Campbell wrote: Nits and Editorial Comments: -- idnits reports: The document seems to use 'NOT RECOMMENDED' as an RFC 2119 keyword, but does not include the phrase in its RFC 2119 key words list. NOT RECOMMENDED is a RFC2119 keyword. The issue

Re: [Gen-art] Gen-ART LC Review of draft-ietf-radext-dtls-11

2014-05-01 Thread Alan DeKok
Ben Campbell wrote: I think it's reasonable to say that good administration practices involve random key generation, and that the interface should not prevent the entry of arbitrary hex strings. But the text says things like When creating keys, it is RECOMMENDED that keys be derived from

Re: [Gen-art] Gen-ART LC Review of draft-ietf-radext-dtls-11

2014-05-01 Thread Brian E Carpenter
On 01/05/2014 23:55, Jouni wrote: On Apr 30, 2014, at 11:39 PM, Ben Campbell wrote: Nits and Editorial Comments: -- idnits reports: The document seems to use 'NOT RECOMMENDED' as an RFC 2119 keyword, but does not include the phrase in its RFC 2119 key words list. NOT RECOMMENDED

Re: [Gen-art] Gen-ART LC Review of draft-ietf-radext-dtls-11

2014-05-01 Thread Brian E Carpenter
On 02/05/2014 00:07, Alan DeKok wrote: ... I'll try to weasel-word the document some more. But it's hard to make the document idiot-proof. If I can chip in, one thing that tends to happen in Gen-ART reviews is that people who have essentially zero knowledge of the topic make a serious effort

Re: [Gen-art] Gen-ART LC Review of draft-ietf-radext-dtls-11

2014-05-01 Thread Alan DeKok
Brian E Carpenter wrote: If I can chip in, one thing that tends to happen in Gen-ART reviews is that people who have essentially zero knowledge of the topic make a serious effort to understand a draft. So they (we) do tend to trip over things that are common knowledge to people active in the

[Gen-art] Gen-ART LC Review of draft-ietf-radext-dtls-11

2014-04-30 Thread Ben Campbell
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-radext-dtls-11 Reviewer: Ben

Re: [Gen-art] Gen-ART LC Review of draft-ietf-radext-dtls-11

2014-04-30 Thread Alan DeKok
Ben Campbell wrote: -- 3.2, last paragraph: I'm still confused about how this is a bid down attack. [The author replied that, when secure and insecure packets are allowed from the same client, a malicious or broken client can choose the insecure one. That's bad, when the intent is to

Re: [Gen-art] Gen-ART LC Review of draft-ietf-radext-dtls-11

2014-04-30 Thread Ben Campbell
Thanks for the quick response. Comments inline, with sections that do not appear to need further content removed. On Apr 30, 2014, at 8:38 PM, Alan DeKok al...@deployingradius.com wrote: Ben Campbell wrote: -- 3.2, last paragraph: I'm still confused about how this is a bid down attack.