Re: KITTEN BOF at IETF 60?
Martin Rex <[email protected]> Wed, 24 Mar 2004 13:59:57 +0100 (MET)
| Newsgroups | gmane.ietf.cat |
|---|---|
| Message-ID | <[email protected]> |
Sam Hartman wrote: > > I'm uncomfortable with the claim that the de facto standardization > level of GSSAPI is full standard. But I don't think it matters > whether I agree with that claim at all. I certainly agree that there > are a lot of GSSAPI V2 applications and mechanisms out there working > today. I agree that breaking these applications or mechanisms would > have a very high cost. I also agree that the API and protocols > described by the GSSAPI V2 documents do work for a large number of > applications. If that's what you mean by de facto standardization > level of full standard, then I agree with what you are saying although > perhaps not the words you are using. > > I'm also uncomfortable with the idea that we cannot change GSSAPI V2 > in a backward incompatible way. I cannot think of a reason at the > current time why it would be a good engineering decision to change > GSSAPI V2 in a backward incompatible way. But I believe the statement > that we cannot do so is false. Nope. You can define a backward-incompatible GSS-API v3, but GSS-API v2 was decided be fully backward compatible to v1 by the CAT working group many years ago. > > Let's say we found a serious security or interoperability problem in > GSSAPI V2. It would be reasonable for us to evaluate the tradeoffs > involved in making a backward incompatible change and there might > exist situations where the costs are justified. There are no security problem in the GSS-API specs. There may be problems in particular mechanisms, but thats a different game. If there are interoperability problems, then the affected feature needs to be marked as optional and have some words of caution added about the encountered interoperability problems and possible solutions or workarounds. > > My personal preference is to work on what I expect to be a GSSAPI V3 > rather than work on advancing the current documents. I don't mind > seeing the protocol and API described by GSSAPI V2 be advanced, I just > don't expect to have time to work on both that task and the extensions > I expect to need for other IETF work. I'm sorry, I didn't meant to imply that it should be your task to progress GSS-API v2 on the standards track. Progressing GSS-API v2 is a seperate task from GSS-API v3 redesign, and it would be more appropriate if the left-overs implementors and users from the previous CAT life took the task of progressing GSS-API v2 while you concentrate on GSS-API v3. -Martin -++**==--++**==--++**==--++**==--++**==--++**==--++**== This message was posted through the Stanford campus mailing list server. If you wish to unsubscribe from this mailing list, send the message body of "unsubscribe ietf-cat-wg" to [email protected]