Draft(s): draft-sparks-sip-nit-problems-02/-actions-03 Reviewer: Elwyn Davies [elwynd@dial.pipex.com] Date: Sunday 6/5/2005 7:26 AM CST Summary: Draft is not ready; security analysis is incomplete. Recommends DISCUSS. Review comments: I reviewed these documents for IETF LC and they have not been updated since. I am told that some changes are in the pipeline in the form of RFC editor notes but I haven't seen them as yet. My reviews suggested that these were useful documents but highlighted two major areas of concern: -,Failure to provide security analysis although it is stated that it has been done in the security considerations section - Informal wording that conceals the true problems rather than explaining them: In particular the analysis of the race condition is just too informal, has somewhat incorrect conclusions and needs to be modified to make it clear (especially to non-English mother tongue readers) what is going on. It may be that the updates will fix these but they certainly need some work. I'll send an update if and when the RFC Editor nodes appear, but otherwise Brian might like to consider a holding DISCUSS on the lack of security analysis.