I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. All my previous comments concerning draft-harkins-emu-eap-pwd-04.txt have been addressed, except perhaps this one: c) There are two places where IANA assigned values need to be filled into the text; perhaps add more explicit RFC editor instructions so the editor knows what to fill in for 'TBD1'. I assume the authors will check carefully during auth48 that correct updates have been made by the RFC editor once IANA has assigned a value. /js -- Juergen Schoenwaelder Jacobs University Bremen gGmbH Phone: +49 421 200 3587 Campus Ring 1, 28759 Bremen, Germany Fax: +49 421 200 3103 < http://www.jacobs-university.de/ >