[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Raven] Q#2: informational



>  "what should the IETF's position be on informational documents that 
>  explain how to perform message or data-stream interception without 
>  protocol modifications".   
>
The official IETF policy on this issue is already described by its RFC-2026 
publication requirement that:

4.2.3  Procedures for Experimental and Informational RFCs
...
   If (a) the IESG recommends that the document be brought within the 
   IETF and progressed within the IETF context, but the author declines 
   to do so, or (b) the IESG considers that the document proposes 
   something that conflicts with, or is actually inimical to, an 
   established IETF effort, the document may still be published as an 
   Experimental or Informational RFC.  In these cases, however, the IESG 
   may insert appropriate "disclaimer" text into the RFC either in or 
   immediately following the "Status of this Memo" section in order to 
   make the circumstances of its publication clear to readers.

It is my position that the IETF should encourage publication of RFCs 
that demonstrate such security lapses, so that they may be repaired  
in future protocol revisions.




_______________________________________________
raven mailing list
raven@ietf.org
http://www.ietf.org/mailman/listinfo/raven