ietf-rats-wg / draft-ietf-rats-msg-wrap

RATS conceptual messages wrapper
Other
0 stars 1 forks source link

Two security considerations #63

Closed thomas-fossati closed 4 months ago

thomas-fossati commented 5 months ago

UCCS is not protected

In https://mailarchive.ietf.org/arch/msg/rats/xY2mwu790UOGnhFAUduGj5ddo3Y/ Carl notes:

"The security considerations section says that “messages themselves and their encoding ensure security protection.” This is not true for UCCS, which is part of the referenced EAT media type spec."

Intra-element binding in collections

In a private conversation between Ned and I:

"[t]here should be a way to ensure the integrity of the collection as soon as the collection is formed.".

Re: intra-element binding, see also: https://www.ietf.org/archive/id/draft-frost-rats-eat-collection-03.html#section-4.1