Re: Gen-art last call review : draft-ietf-geopriv-deref-protocol-03
"Thomson, Martin" <[email protected]> Thu, 3 Nov 2011 06:18:10 +0800
| Newsgroups | gmane.ietf.gen-art,gmane.ietf.geopriv |
|---|---|
| Message-ID | <27AFD040F6F8AA4193E0614E2E3AF9C910D7C1F1B2@SISPE7MB1.commscope.com> |
On 2011-11-03 at 08:15:01, Robert Sparks wrote: > (Including the geopriv list on this reply). > > Martin - there's one change you made that I think you need to adjust. > In response to Elwyn's suggestion about Appendix A, Req 9 below, > you've added some 2119 text to that appendix which isn't right. Is > there a place you can say what you want to say in the body of the document? Yeah, and that was stupid of me. The security considerations already contains a statement to this effect: Location URIs MUST only be disclosed to authorized Location Recipients. As for the 2119 language, a reference to the above statement should do: OLD: In order to comply with these rules, a Location Recipient MUST NOT redistribute a location URI without express permission. Depending on the access control model, the location URI might be secret (see Section 3.3 of [RFC5808]). NEW: For location URIs that are use possession as a component of authorization, the protecting the secrecy of the URI is necessary in order to comply with this requirement (see Section 6). --Martin