Re: [Ace] Last Call: (EAP-based Authentication Service for CoAP) to Proposed Standard

2024-01-25 Thread Dan Garcia Carrillo
Dear Carsten, Thank you very much for the comments. Yes, you are correct. The content of the array contains a non-empty list of RFC 9052 algorithm identifiers. There is a case, where the element representing the list is not sent, that is intended to signify that the default cipher suites are c

Re: [Ace] Secdir last call review of draft-ietf-ace-wg-coap-eap-09

2024-01-25 Thread Dan Garcia Carrillo
Dear Deb, Thank you for the update on the review. Please let us comment inline. El 23/1/24 a las 13:07, Deb Cooley via Datatracker escribió: Reviewer: Deb Cooley Review result: Has Nits I have reviewed this document as part of the security directorate's ongoing effort to review all IETF docum

Re: [Ace] Secdir last call review of draft-ietf-ace-wg-coap-eap-09

2024-01-25 Thread Deb Cooley
My 5.1 comment: I skimmed RFC 4017 and it seems sufficient. I also looked to see if EAP methods include it as a reference (and many of them do). It is my opinion that w/ the addition of a reference and some clarifying text will allow you to claim that the MSK is a 'strong cryptographic key', and

Re: [Ace] Secdir last call review of draft-ietf-ace-wg-coap-eap-09

2024-01-25 Thread Dan Garcia Carrillo
Great, thank you. Best regards. El 25/1/24 a las 14:26, Deb Cooley escribió: My 5.1 comment:  I skimmed RFC 4017 and it seems sufficient.  I also looked to see if EAP methods include it as a reference (and many of them do).  It is my opinion that w/ the addition of a reference and some clari