Hi Dan, Thank you for your review. Please see below for responses to your comments. Kent
Your understanding is correct, the document regards device identity certificates in a generic X.509v3 sense. Actually, a careful reading of 802.1AR shows that it, effectively, says the same, placing very few (if any) restrictions on the contents of the X.509v3 certificate. That said, 802.1AR did define the terms “IDevID” and “LDevID”, which have become fairly well known in the industry. Thusly, this document attempts to capitalize on that familiarity w/o stating that identity certificates MUST be 802.1AR-compliant. Throughout the body of the document, the text consistently uses phraseology such as “an initial device identity certificate (e.g., an IDevID from 802.1AR)” that simultaneously doesn't bind implementations to a particular identity-certificate definition while remaining highly understandable. However, the text in the YANG module uses a different approach, out of a sense if brevity, by using the terms IDevID/LDevID directly (w/o any parenthetical reference to 802.1AR), along with the terminology-disclaimer you copy/pasted above. Whilst the document appears technically accurate/unambiguous, the issue seems to warrant a remedy, as the SecDir-review made a similar comment. Options: 1) Define formal terms for IDeviD and LDevID in Section 1.2 (Terminology) stating that 1) they are acronyms for “initial/local device identifier” and 2) they are consistent with the same terms in 802.1AR but do not imply that any implementation must adhere to 802.1AR. This update could be coupled with the removal of all the parenthetical phraseology throughout the body of the document. 2) Modify the YANG module to 1) also use the parenthetical phraseology (greatly expanding the verbosity of the “description” statement text) and 2) remove the quoted terminology-disclaimer at the top of the YANG module. 3) Do nothing. Which option seems best? Does anyone have. preference? Kent // co-author |
-- last-call mailing list last-call@xxxxxxxx https://www.ietf.org/mailman/listinfo/last-call