I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. This draft describes the requirements for providing an IMAP interface for IETF mail archives. The first item in the security considerations is correct, but in general the security considerations seem too narrowly focused on searching and storage. Some discussion of the following may be worthwhile: how the server is authenticated to users, how users are authenticated to the server (unless the reference to the datatracker system is viewed as sufficient), details of the interface with the datatracker authentication system, (maybe) how archive integrity is maintained, identification of what should or should not be logged.