Document: draft-josefsson-kerberos5-starttls-07.txt Reviewer: Miguel Garcia Review Date: 14-Dec-2009 IETF LC End Date: 24-Dec-2009 Summary: The document is ready for publication as an informational RFC. It came as a surprise that a protocol that is used to enhance the security ends up saying that protocol does not require clients to verify the server certificate. It sounds strange, but I think it is well justified. Nits/editorial comments: - Expand acronyms at first occurrence. This includes: SRP - Section 5, 6th paragraph: s/a list that map realm names/a list that maps real names ^^^^