Re: [TLS] Comments on draft-housley-tls-authz-extns-07
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Comments on draft-housley-tls-authz-extns-07



>>>>> "Dean" == Dean Anderson <dean at av8.com> writes:

    Dean> I believe the IETF announced that it would be sending this
    Dean> draft back to the 'starting gate'.  To me, that means that
    Dean> TLS has to do several things:

Dean, Eric has corrected your statements about where this draft is in
the process.  However I do want to respond to a couple of your
comments.

    Dean> 1) Consider non-patented alternatives in accordance with
    Dean> RFC2418 and RFC3979.

Dean, this is an excellent idea.
Anyone who wants to including you can discuss alternatives to the technology.
The availability of other ways to do this--particularly when combined with information about whether people are willing to do the necessary work to write up and implement these alternatives--would be great input to the IESG.
I'd appreciate anything you can do in this regard.

As an example, if all the implementers say that they prefer this
solution to alternatives they have considered, and would implement
this solution but not those alternatives, that would be a strong
argument in favor of publication.  If on the other hand people say
that they would write up an alternative and that they would implement
the alternative, that would argue against publication.


What you may be assuming is that we have an obligation to conduct such
a review or that we need to block our work until such a review is
done.  We do have an obligation to consider any alternatives that are
brought forward.  We do have an obligation to solicit comments so
people know they can bring forward alternatives.  But if no one
actually brings forward an alternative we don't have to sit around
waiting.

so if you want to propose an alternative, you should do so.  If you
know others who want to propose an alternative you should encourage
them.




    Dean> 2) Obtain a thorough review and consensus per RFC2026 and
    Dean> RFC2418.

RFC 2418 does not directly apply because this is not a WG document.
However you are completely correct that we need to obtain a consensus.

That's why we are soliciting comments.  The ietf list discussion was
in the minds of some inconclusive.  We're soliciting review here in
hopes that the discussion will lead to a clear consensus.

    Dean> 3) Pass a working group last-call, per RFC2026 and RFC2418.

Not applicable because this is not a WG document.

Thanks for your valuable input.

Sam Hartman
Security Area Director


_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.