[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: pre-kink-10
Hi,
I think that this sentence should not be in the introduction,
should be in the security consideration that Ken mentioned.
On the other hand, there is a same sentence in the security
consideration. So we might be able to just remove it.
However the sentence was added after a IESG review. Thus I do not
know we can remove it easily.
Derek, could you decide whether it can remove or not ?
> > Relatively minor stuff:
> >
> > - Introduction:
> >
> > Kerberos, like any internet protocol, does have
> > its own security considerations. You can find them discussed in
> > [KERBEROS].
> >
> > That's security-considerations material, not introductory
> > material. In fact, I think the security considerations section
> > already talks about it.
>
> These sentences seem to have been added as a result of the
> previous IESG review, for a comment from Randy Bush.
> <https://datatracker.ietf.org/public/pidtracker.cgi?command=view_comment&id=9126>
> (See the first comment.)
> I feel he was not focusing on security vulnerabilities (as he gave
> scalability as an example).
> So, I'll replace that part with the following.
>
> Kerberos, like any internet protocol, does have drawbacks on certain
> environments. You can find them discussed in [KERBEROS] and its
> references.
>
> Do you have better sentences?