I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. I apologize for doing this so late. This document defines how to use TLS to secure NETCONF exchanges. I don't have any security issues but I do I have a question about the last paragraph in 2.1. It says that TLS 1.2 MUST be supported and that future versions of TLS will also be supported and those mandatory to implement algorithms MUST also be supported. is that also saying that an implementation must support all future version of TLS too? spt