Re: Gen-art last call review : draft-ietf-geopriv-deref-protocol-03

"Thomson, Martin" <[email protected]> Thu, 3 Nov 2011 06:18:10 +0800
Newsgroups gmane.ietf.gen-art,gmane.ietf.geopriv
Message-ID <27AFD040F6F8AA4193E0614E2E3AF9C910D7C1F1B2@SISPE7MB1.commscope.com>
On 2011-11-03 at 08:15:01, Robert Sparks wrote:
> (Including the geopriv list on this reply).
> 
> Martin - there's one change you made that I think you need to adjust.
> In response to Elwyn's suggestion about Appendix A, Req 9 below, 
> you've added some 2119 text to that appendix which isn't right. Is 
> there a place you can say what you want to say in the body of the document?

Yeah, and that was stupid of me.

The security considerations already contains a statement to this effect:

   Location URIs MUST only be disclosed to authorized Location
   Recipients.  

As for the 2119 language, a reference to the above statement should do:

OLD:
   In order to comply with these rules, a Location Recipient	
   MUST NOT redistribute a location URI without express	
   permission. Depending on the access control model, the	
   location URI might be secret (see Section 3.3 of	
   [RFC5808]).
NEW:
   For location URIs that are use possession as a component of
   authorization, the protecting the secrecy of the URI is
   necessary in order to comply with this requirement (see
   Section 6).

--Martin