On 7/8/14, 9:21 PM, Vincent Chen wrote:
I'll be in Toronto if you want to talk about any of these. Some small comments inline:
Well, your security considerations, at least, should talk about what you require of the transport if you don't use TLS. You're leaning heavily on TLS for things like server authentication for example. The group will have to chew on this I guess. You can't forbid HTTP-level 3xx responses, and you still want well defined application behavior when they're received.
Check with your AD on the best way to handle this. So, you can't gain information about someone else by claiming to be their device type either? Consider calling out the possibility of SPECTRUM_USE_NOTIFY messages that are fraudulent (and perhaps how client authentication might protect against them)? Just adding a short description of the properties that you require of id.
|