I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. draft-ietf-kitten-rfc6112bis-02 is an update that obsoletes RFC 6112. It's a copy of 6112 with a few corrections, some word-smithing and a small amount of new text. A few minor comments are below: - RFC6112 should appear in the bibliography. - I'd add a few more items to section 1.1 (changes since 6112) to call out the corrections to type names from RFC4556 and highlight the KeyExchange->KEYEXCHANGE change. Rationale for the MUST->SHOULD change might be nice here too. - The IANA considerations section was right in 6112, but probably doesn't belong here (at not least as defining a 'new' well-known name).