[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

IESG has approved 2 documents



The IESG has now approved these documents:

>    draft-ietf-rap-signaled-priority-v2-00.txt
>    draft-ietf-rap-rsvp-newidentity-01.txt
> 
We have added the attached notes to RFC-Editor:

Thanks to the Authors/editors and the WG for your work and patience.

Bert

> ----------------------------------------------------
> Note to RFC-Editor:
> 
> for document draft-ietf-rap-signaled-priority-v2-00.txt
> 
> - On title page, pls change "replaces RFC 2751" with 
>   "Obsoletes RFC 2751"
> - Pls add a reference to RFC2571 as well.
> 
> for document draft-ietf-rap-rsvp-newidentity-01.txt
> 
> - add this IESG note to the title page
> 
> > IESG NOTE: The use of digital signatures, as (for example) described 
> > in section 3.3.3 provides inadequate protection against a cut-and-paste
> > form of replay attack, even when used in connection with the INTEGRITY
> > object. This is due to the lack of cryptographic "freshness" guarantees 
> > in the AUTH_DATA object. In fact this weakness exists for any policy
> > data object transported with this mechanism. 
> > A future version of this document and related documents will
> > address this serious shortcoming.
> > 
> - move last sentence of section 1. to abstract section 
>   (make it last sentence in that section).
> 
> - Pls add a reference to RFC2752 too.
> 
> Thanks,
> Bert
>