Skip to main content

Last Call Review of draft-ietf-core-oscore-edhoc-09
review-ietf-core-oscore-edhoc-09-genart-lc-halpern-2023-11-12-00

Request Review of draft-ietf-core-oscore-edhoc
Requested revision No specific revision (document currently at 11)
Type Last Call Review
Team General Area Review Team (Gen-ART) (genart)
Deadline 2023-11-13
Requested 2023-10-23
Authors Francesca Palombini , Marco Tiloca , Rikard Höglund , Stefan Hristozov , Göran Selander
I-D last updated 2023-11-12
Completed reviews Opsdir Telechat review of -10 by Jürgen Schönwälder (diff)
Secdir Telechat review of -10 by Wes Hardaker (diff)
Artart Telechat review of -10 by Shuping Peng (diff)
Iotdir Telechat review of -10 by Emmanuel Baccelli (diff)
Artart Last Call review of -09 by Shuping Peng (diff)
Opsdir Last Call review of -09 by Jürgen Schönwälder (diff)
Secdir Last Call review of -09 by Wes Hardaker (diff)
Genart Last Call review of -09 by Joel M. Halpern (diff)
Assignment Reviewer Joel M. Halpern
State Completed
Request Last Call review on draft-ietf-core-oscore-edhoc by General Area Review Team (Gen-ART) Assigned
Posted at https://mailarchive.ietf.org/arch/msg/gen-art/wGULQiHog2vignuDLkMVi69C3yY
Reviewed revision 09 (document currently at 11)
Result Ready w/issues
Completed 2023-11-12
review-ietf-core-oscore-edhoc-09-genart-lc-halpern-2023-11-12-00
I am the assigned Gen-ART reviewer for this draft. The General Area
Review Team (Gen-ART) reviews all IETF documents being processed
by the IESG for the IETF Chair.  Please treat these comments just
like any other last call comments.

For more information, please see the FAQ at

<https://wiki.ietf.org/en/group/gen/GenArtFAQ>.

Document: draft-ietf-core-oscore-edhoc-09
Reviewer: Joel Halpern
Review Date: 2023-11-12
IETF LC End Date: 2023-11-13
IESG Telechat date: Not scheduled for a telechat

Summary: This document is ready for publication as a proposed standard
reviewer note: I did not attempt to verify that the description here of the
underlying security protocols is correct.  I leave that to the WG and the
security reviewers.

Major issues: N/A

Minor issues:
   In reading the first part of section 3, I found myself confused in two
   regards.  First, the diagram shows the third message as containing EDHOC
   message_3 + OSCORE-protected data. But the text refers to it as also
   containing C_R which is not apparently part of EDHOC message 3.  I think
   this is explained in step 4 of section 3.2, but it is at best jarring at
   this stage. (Maybe just call it OSCORE option C_R? Or note at this point,as
   you do later, in the text that the EDHOC C_R and the OSCORE C_R are
   identical?)
    Second, the description here is worded in a way that leads the reader to
    understand that the EDHOC message is part of the OSCOR content.  The
    processing order and protection structure is spelled out in section 3.2. 
    Maybe just add something like "This structure can be processed in order due
    to the construction rules in section 3.2?

Nits/editorial comments: