[Gen-art] Gen-ART review of draft-ietf-pkix-caa-10

2012-07-06 Thread Richard L . Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-pkix-caa-10 Reviewer: Richard

[Gen-art] Gen-ART LC review of draft-ietf-nfsv4-federated-fs-admin-11

2012-06-19 Thread Richard L . Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-nfsv4-federated-fs-admin-11

[Gen-art] Gen-ART Telechat review of draft-ietf-appsawg-about-uri-scheme-05

2012-06-04 Thread Richard L . Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-appsawg-about-uri-scheme-05

[Gen-art] Fwd: Gen-ART review of draft-ietf-dnsext-dnssec-bis-updates-18

2012-05-25 Thread Richard L. Barnes
Forgot to copy gen-art. Begin forwarded message: From: Richard L. Barnes rbar...@bbn.com Subject: Gen-ART review of draft-ietf-dnsext-dnssec-bis-updates-18 Date: May 25, 2012 5:02:28 PM EDT To: IESG i...@ietf.org, i...@ietf.org Cc: draft-ietf-dnsext-dnssec-bis-upda...@tools.ietf.org I am

[Gen-art] Gen-ART Telechat review of draft-ietf-oauth-v2-25

2012-04-10 Thread Richard L . Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Document: draft-ietf-oauth-v2.txt Reviewer: Richard Barnes Review Date: 10 Apr 2012 IETF LC End Date: IESG Telechat Date: 12 Apr 2012

[Gen-art] Gen-ART review of draft-ietf-payload-rtp-klv-02

2012-01-26 Thread Richard L . Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-payload-rtp-klv-02 Reviewer:

[Gen-art] Gen-ART review of draft-ietf-6lowpan-nd-18

2011-12-30 Thread Richard L . Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-6lowpan-nd-18 Reviewer:

[Gen-art] Gen-ART Telechat Review of draft-ietf-hokey-arch-design-03

2011-11-23 Thread Richard L. Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please wait for direction from your document shepherd or AD before posting a new version of the draft. Document:

Re: [Gen-art] Gen-ART review of draft-ietf-geopriv-policy-uri-02

2011-10-22 Thread Richard L. Barnes
Hi David, Thanks for your review. Glad to provide clarification on these points. Responses inline below. Let me know if these address your concerns. --Richard This draft specifies policy URIs for management of privacy policy for location information obtained and maintained by Location

Re: [Gen-art] Gen-ART review of draft-ietf-geopriv-policy-uri-02

2011-10-22 Thread Richard L. Barnes
Hi David, Thanks for your review. Glad to provide clarification on these points. Responses inline below. Let me know if these address your concerns. --Richard This draft specifies policy URIs for management of privacy policy for location information obtained and maintained by Location

Re: [Gen-art] [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-06 Thread Richard L. Barnes
Section 5.6, Note that a particular text frame might include a partial UTF-8 sequence, however the whole message MUST contain valid UTF-8 This requirement is meaningless, since the concept of a message is not defined here. Suggest going back to a requirement that a frame MUST contain

Re: [Gen-art] [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-06 Thread Richard L. Barnes
No, you have to process at most three bytes, four if you include the opcode. See sample code. --Richard On Sep 6, 2011, at 10:47 AM, Willy Tarreau wrote: On Tue, Sep 06, 2011 at 10:43:38AM -0400, Richard L. Barnes wrote: Clearly it already has to be WebSocket aware, and it already has

Re: [Gen-art] [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-06 Thread Richard L. Barnes
Section 2, Implementations MAY impose implementation-specific limits... This paragraph has been removed in -13. No, it got moved to its own section Implementation-Specific Limits under the Security Considerations Yeah, sorry, wrote that before I got to the Security Considerations :)

Re: [Gen-art] [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-06 Thread Richard L. Barnes
On Sep 6, 2011, at 10:58 AM, Tobias Oberstein wrote: In contrast, *not* requiring breaking at UTF-8 code points means that clients can't do any meaningful validation on text frames. Which means you might as well get rid of text frames entirely. Why? You can do streaming validation of

Re: [Gen-art] [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-06 Thread Richard L. Barnes
I strongly propose changing the meaning of 1007 status code from: 1007 indicates that an endpoint is terminating the connection because it has received data that was supposed to be UTF-8 (such as in a text frame) that was in fact not valid UTF-8 [RFC3629]. to: 1007

Re: [Gen-art] [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-06 Thread Richard L. Barnes
While the MAY doesn't specify a requirement, it seems like it would be helpful to implementers in light of the exhaustion/DoS possibilities presented by huge frames and fragmentation. I would even argue that it Why should that impose exhaustion/DoS possibilities? A WS impl. offering a

Re: [Gen-art] [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-06 Thread Richard L. Barnes
Well, ok. No state related to UTF-8. Any intermediary that deals with fragmentation will have to remember the opcode/extensions. --Richard On Sep 6, 2011, at 12:38 PM, Bjoern Hoehrmann wrote: * Richard L. Barnes wrote: If frames are valid utf-8, then you don't need to keep any state

Re: [Gen-art] [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-06 Thread Richard L. Barnes
In total: 3 bits: opcode of first frame 1 bit: continuation state 4 bit: UTF-8 DFA state 1 octet state forgot of course: for servers: client mask (4 octets) last frame end % 4 : 2 Bits = to know where within mask to start for unmasking the next masked frame

Re: [Gen-art] [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-06 Thread Richard L. Barnes
to SlowLoris if they imposed limits on the number of HTTP headers of the length of time that a request must take? All I'm suggesting is that this document suggest similar good habits. --Richard On Sep 6, 2011, at 1:37 PM, IƱaki Baz Castillo wrote: 2011/9/6 Richard L. Barnes rbar...@bbn.com

Re: [Gen-art] [hybi] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-06 Thread Richard L. Barnes
While the MAY doesn't specify a requirement, it seems like it would be helpful to implementers in light of the exhaustion/DoS possibilities presented by huge frames and fragmentation. I would even argue that it should be a SHOULD. I am Ok with changing MAY to SHOULD. I'm

[Gen-art] Gen-ART LC review of draft-ietf-lisp-map-versioning-02

2011-09-02 Thread Richard L . Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-lisp-map-versioning-02.txt

[Gen-art] Review of draft-ietf-hybi-thewebsocketprotocol-13

2011-09-02 Thread Richard L. Barnes
Hey all, I was selected for the Gen-ART review of draft-ietf-hybi-thewebsocketprotocol, and submitted a review during IETF LC: Since it's coming up for telechat, I thought I would give it a second look. Comments on the diff are below. --Richard Section 2, Implementations MAY impose

[Gen-art] Gen-ART telechat review of draft-ietf-yam-rfc44099bis-02

2011-08-22 Thread Richard L. Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-yam-rfc44099bis-02

[Gen-art] review of draft-ietf-opsawg-mib-floats-02.txt

2011-06-20 Thread Richard L. Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-opsawg-mib-floats-02.txt

[Gen-art] Gen-ART Telechat review of draft-paxson-tcpm-rfc2988bis-02

2011-04-22 Thread Richard L. Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please wait for direction from your document shepherd or AD before posting a new version of the draft. Document:

Re: [Gen-art] Ge-ART LC review of draft-zhu-mobility-survey-

2011-03-07 Thread Richard L. Barnes
mentioned. Thanks, Zhenkai On Feb 28, 2011, at 5:45 PM, Richard L. Barnes wrote: I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please wait for direction from your document

Re: [Gen-art] Ge-ART LC review of draft-zhu-mobility-survey-

2011-03-07 Thread Richard L. Barnes
That's fine, just thought it would be an interesting area to discuss. --Richard On Mar 7, 2011, at 3:36 PM, Lixia Zhang wrote: On Mar 7, 2011, at 12:22 PM, Richard L. Barnes wrote: Zhenkai, Thanks for following up. With regard to security/NATs: These could be relevant in your

[Gen-art] Ge-ART LC review of draft-zhu-mobility-survey-

2011-02-28 Thread Richard L. Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please wait for direction from your document shepherd or AD before posting a new version of the draft. Document:

[Gen-art] Gen-ART review of draft-groves-sakke-00

2011-01-04 Thread Richard L. Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-groves-sakke-00 Reviewer: Richard

[Gen-art] Gen-ART review of draft-ietf-avt-srtp-big-aes-05

2010-12-11 Thread Richard L . Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-avt-srtp-big-aes-05 Reviewer:

Re: [Gen-art] Gen-ART LC review of draft-ietf-httpstate-cookie-18

2010-11-29 Thread Richard L. Barnes
Hey Adam, Thanks for following up. Responses inline. [S8.6] Many of these integrity issues are caused by user agents accepting cookies from outside the context where they would send them, in particular with the Secure and Path attributes. It seems like this document, in specifying the

Re: [Gen-art] Gen-ART LC review of draft-ietf-httpstate-cookie-18

2010-11-29 Thread Richard L. Barnes
Hey Adam, I'm OK letting the remainder of these go as you prefer. Thanks for working this through with me. --Richard On Nov 29, 2010, at 7:04 PM, Adam Barth wrote: On Mon, Nov 29, 2010 at 3:18 PM, Richard L. Barnes rbar...@bbn.com wrote: Minor issues: [General] It would be very

[Gen-art] Gen-ART LC review of draft-ietf-httpstate-cookie-18

2010-11-28 Thread Richard L. Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-httpstate-cookie-18 Reviewer:

[Gen-art] Gen-ART review of draft-ietf-netconf-with-defaults-12.txt

2010-10-25 Thread Richard L. Barnes
I have been selected as the General Area Review Team (Gen-ART) reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq Please resolve these comments along with any other comments you may receive. Document:

[Gen-art] Gen-ART LC Review of draft-ietf-tcpm-urgent-data-06

2010-09-14 Thread Richard L. Barnes
I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq. Please resolve these comments along with any other Last Call comments you may receive. Document: draft-ietf-tcpm-urgent-data-06

Re: [Gen-art] draft-ietf-geopriv-arch-02.txt

2010-08-17 Thread Richard L. Barnes
Francis, Thanks for your review. We'll try to get the issue you note resolved with RFC editor notes. --Richard On Jul 19, 2010, at 10:56 AM, Francis Dupont wrote: I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at